Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 18 Mar 2003 13:33:31 -0800 (PST)
From:      Julian Elischer <julian@elischer.org>
To:        re@freebsd.org, hackers@freebsd.org
Subject:   rumour of password aging failure in 4.7/4.8RC
Message-ID:  <Pine.BSF.4.21.0303181250540.79971-100000@InterJet.elischer.org>

next in thread | raw e-mail | index | archive | help

I've received a few reports from teh field that password aging
with ssh in 4.7 and 4.8RC is broken.

Is there anyone out there that is using passwork expiry 
and ssh? Who's the expert?


The method being used:
Define a class called the shellusers class in the /etc/login.conf.
Run cap_mkdb on the login.conf file
Go into the master.passwd file and expired an account.

According to our clients, after the account is expired SSH on 4.7
disallows any logins. It is supposed to allow your connection and then
just force you to change your password. On 4.8-RC ssh seems to be
totally ignoring the fact that the password is expired.
"login" on the other hand acts as expected.

Is this the correct procedure? (If not, what IS the correct proceedure?
Where is password expiry documented? (man login.conf and man passwd
seem the best references so far..).

How does PAM come into this?

The older version of SSH we have on the 4.4 boxes works with
the same password expiration set up without any problems.



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-hackers" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0303181250540.79971-100000>