LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 12-21-2021, 10:45 AM   #16
computersavvy
Senior Member
 
Registered: Aug 2016
Posts: 3,345

Rep: Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484Reputation: 1484

I agree with pan64. There could be a password checker in place to verify the strength of the password when entering a new password. Many places do that, and it seems to be relatively simple.

In fact, if you are signing in on line to a government web site they often have rules about the password strength, length, and expiration as well as preventing reuse of the same password for a certain number of times. My bank does the same.

It should not be difficult to put something of that nature in place for passwords on the servers and then just verifying it is in place and working would meet the security checklist requirements. Seems like it would be a wrapper around or replacement of the passwd command on the server and probably already exists somewhere.

It should work for all users since many on a server may have sudo access and their user password would need to be as secure as the root password.
 
Old 12-22-2021, 07:05 PM   #17
denhooker56
LQ Newbie
 
Registered: May 2021
Posts: 4

Rep: Reputation: 0
I do not know if any encrypted record or file is generated that can show any indication of it.
 
Old 12-24-2021, 08:17 PM   #18
androsob
LQ Newbie
 
Registered: Dec 2021
Location: Lima, Perú
Distribution: Ubuntu
Posts: 8

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by computersavvy View Post
My bank does the same.
At my job, we still have the policies on the complexity of passwords. But like I told you, when I asked for some root passwords I almost went flat on my back.

It seems like a good idea to have a tool that evaluates the complexity of the password at the beginning of 'creating' it, but when we already have an infrastructure with more than 4k servers it is more complex.

I wanted to do a quieter job and audit the server from my side but it looks like I will have to audit the keys directly with the corresponding area.
 
Old 12-25-2021, 02:19 AM   #19
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,892

Rep: Reputation: 7317Reputation: 7317Reputation: 7317Reputation: 7317Reputation: 7317Reputation: 7317Reputation: 7317Reputation: 7317Reputation: 7317Reputation: 7317Reputation: 7317
with more than 4k servers you must have an automated way to install/configure that tool.
Checking those passwords directly/manually is insecure, unreliable, not really acceptable by audits and also not really feasible on 4k servers. But you know.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
setting password complexity not working as root cheersvega Linux - Server 1 08-24-2012 01:22 AM
bash script to test string complexity (like password complexity) robertjinx Linux - Server 2 05-12-2010 02:58 PM
[SOLVED] root password complexity enforcement ErnieG Linux - Security 3 05-05-2010 06:45 AM
Howto change system password policies (passwd length, complexity) tisource Linux - Security 3 09-06-2005 12:01 AM
Linux PAM minimum password and complexity reemo73 Linux - Software 3 06-01-2005 03:22 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 04:05 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration