diff options
author | Timo Weingärtner <timo@tiwe.de> | 2024-06-17 12:25:16 +0200 |
---|---|---|
committer | Timo Weingärtner <timo@tiwe.de> | 2024-06-17 12:25:16 +0200 |
commit | 55ddea494b0c7c316461ac9b7b4139af4b175b21 (patch) | |
tree | 3f53d534716a1285b0374eef6adf35b886f64c6d /README | |
parent | 20920cef5ace15e398fdb2d51a8448bee3c096d3 (diff) | |
parent | 2347ef0edd7054d3df9838612aa78ac6bd077dfd (diff) | |
download | libpam-pwdfile-55ddea494b0c7c316461ac9b7b4139af4b175b21.tar.gz |
Merge tag 'v2.0' into debian
release 2.0
Diffstat (limited to 'README')
-rw-r--r-- | README | 17 |
1 files changed, 0 insertions, 17 deletions
@@ -25,7 +25,6 @@ options * debug: produce a bit of debug output * nodelay: don't tell the PAM stack to cause a delay on auth failure * flock: use a shared (read) advisory lock on pwdfile, you should better move new versions into place instead -* legacy_crypt: see section LEGACY CRYPT PASSWORD FILE @@ -36,19 +35,3 @@ First field contains the username, the second the crypt()ed password. Other fields are optional. crypt()ed passwords in various formats can be generated with mkpasswd from the whois package. - - -LEGACY CRYPT -============ - -There are two crypt types that are disabled by default: bigcrypt and broken md5_crypt. -They are disabled because they use static buffers which is bad when doing PAM authentication using this module in a multithreaded server. -All the other crypt types are checked via the systems crypt_r function if available, else with the normal crypt function and the same static-buffer-problem. - -bigcrypt was used on DEC systems to allow for longer passwords. -You can check if your passwd file contains any of these with `cut -d: -f2 passwd-file | egrep '^[^$].{13}'`. - -Broken md5_crypt is a speciality of big-endian systems. -An early implementation of md5_crypt got the byte order wrong here and produced different crypt outputs. -You might have some of these crypt hashes in your passwd file only if you created them on a big-endian system. -If an md5_crypt hash also worked on a little-endian system (up to and including libpam-pwdfile 0.99) it isn't broken md5_crypt. |