Re: Upgrading password hashes

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On Thu, Jul 12, 2012 at 7:21 AM, C Anthony Risinger <anthony@xxxxxxx> wrote:
> However PAM, also by design, works in stacks, and thus offers a reasonable
> solution -- update the `auth` and `password` PAM keys to the new algo (so
> new passwords are read/written properly) then duplicate the `auth` key,
> restore the original algo, and change `required` -> `sufficient`).  This
> would accept the old (higher in stack, sufficient) hash until that line was
> removed.

Are you sure the `auth` part is necessary? As far as I know, pam_unix
accepts /all/ hash formats supported by system; the configured hash is
only necessary for creating new hashes in `password`.

-- 
Mantas Mikulėnas


[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]
  Powered by Linux