LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-17-2016, 10:17 AM   #1
gazroobari
LQ Newbie
 
Registered: Aug 2016
Posts: 8

Rep: Reputation: Disabled
Changing password authentication from DES to SHA 512


I have an embedded ELDK controller which is currently operating on the basis of DES password authentication. None of the /etc/shadow entries have a password field which is prefixed with ${digit}$.

Purely for improved security and the need to integrate with some third-party software, I need to change the authentication type to SHA-512, and I am roughly aware of what needs modifying in login.defs to do that.

However, I'm concerned as to what will happen when I reboot after the change. Do existing password entries get left intact as they are ?

If so, I'm happy with that, because there aren't that many users that would need the password re-encrypting. And it would probably answer the other concern I have about root access, i.e. presumably, I won't lose the ability to log back in with my existing root user ?

Thanks
 
Old 08-17-2016, 03:15 PM   #2
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Open two sessions to the server.
Work in one. test, Disconnect, Reconnect.
Don't disco the 2nd session until you are certain in the first.

Welcome to LQ!
 
Old 08-18-2016, 05:20 AM   #3
gazroobari
LQ Newbie
 
Registered: Aug 2016
Posts: 8

Original Poster
Rep: Reputation: Disabled
@Habitual Thanks for the welcome. I'm normally a Java developer so this project is a bit out of my normal comfort zone! Can I take you up on your reply ? My primary connection to the controller is putty via serial to the controller's RS232 'debug' port. The controller also runs an ssh server which I can putty into over IP. However, I am assuming your paradigm of 'test, disconnect, reconnect' implies a controller reboot after modification of login.defs and so, surely, I will lose the second connection at that point ?

Thanks
 
Old 08-18-2016, 06:50 AM   #4
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
I misunderstood the question. Sorry.
 
Old 08-18-2016, 05:51 PM   #5
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939
Slightly-puzzled here because DES is an encryption algorithm, whereas SHAx is a digital-signature algorithm ... apples and oranges ...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: OpenSSH 7.2 Out Now with Support for RSA Signatures Using SHA-256/512 Algorithms LXer Syndicated Linux News 0 02-29-2016 08:40 AM
[SOLVED] How do you encrypt a USB partition with the Twofish cipher and SHA-512 hash? Cinematography Linux - Security 1 05-31-2014 07:41 PM
How can I convert a sha-512 /etc/shadow hash to base64? abefroman Linux - Security 1 09-15-2013 10:47 AM
[SOLVED] How to use an encrypted sha-512 bootloader password in Kickstart script ? Rogue45 Linux - Server 1 05-02-2013 12:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:27 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration