LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 01-31-2005, 11:52 AM   #1
news2me
LQ Newbie
 
Registered: Jan 2005
Posts: 2

Rep: Reputation: 0
Question relaxing password credentials in RH 3 ent


Hi All...

I am having a issue when it comes to password security in RH 3 ent. I am trying to relax or make the ability to have people create simple passwords w/o having to use complex char and numbers.

I looked in the forums and they don't touch this type of issue or I have not found the post yet.


Any help would be appreciated.... !!!


Thanks,
 
Old 02-01-2005, 12:30 AM   #2
subhasis_ray
Member
 
Registered: Jul 2001
Location: india
Distribution: RedHat 7.1,7.2,7.3, 8.0,9.0,Fedora,EL2.1,EL3.0
Posts: 103

Rep: Reputation: 16
Thats a real bad idea...... Relaxing passwd security may make life easier for your users..... but it also makes getting into your machine easier....

I would suggest that u explain the situation to your users. I am sure that they will understand..

Cheers

Subhasis
 
Old 02-02-2005, 04:52 PM   #3
Builder
Member
 
Registered: Jun 2004
Location: London
Distribution: Red Hat, SuSE, Gentoo
Posts: 80

Rep: Reputation: 15
Have a look in
/etc/pam.d/system-auth

Look for a line that says something about cracklib

Comment that out, and then see if passwd will allow you to set simple passwords.

I do however agree with Subhasis about this being a bad idea - if you relax passwords too much, you will end up getting cracked by brute force tools like the SSH scanners we are currently seeing all over the place.

Of course, the flip side is that if you enforce complex passwords, you have the risk of users writing them on post it notes.

One thing I find as good advice to users is to choose a phrase and use the first letter of each word in their password. Make one of the letters uppercase, and replace one letter with a digit. This seems to work well for most of my users.

As an example, a password derived from
I have real trouble remembering good passwords
would become
1Hrtrgp
 
Old 02-03-2005, 09:19 AM   #4
news2me
LQ Newbie
 
Registered: Jan 2005
Posts: 2

Original Poster
Rep: Reputation: 0
Smile relaxing password

Thanks all for the input... Yeah there is a security issue but we have a company program that utilizes the password script in linux and it can't deal with complex passwords.

The crack worked for "/etc/pam.d/system-auth" ...

Thanks Again...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LDAP_BIND: Invalid Credentials rupesh_pulikool Linux - Software 0 02-01-2005 01:27 PM
ldap invalid credentials johond Linux - Networking 1 12-14-2004 04:31 AM
ldap: invalid credentials johond Debian 0 12-14-2004 04:00 AM
different credentials alaios Linux - General 2 10-03-2004 02:03 PM
ldap_bind:Invalid credentials chintone Linux - General 0 12-06-2002 05:42 AM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 10:30 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration