LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Cracklib defaults (https://www.linuxquestions.org/questions/linux-security-4/cracklib-defaults-4175533535/)

adamp_oh 02-09-2015 04:02 PM

Cracklib defaults
 
Regarding the various parameters one can use to configure password parameters with cracklib, are there any "defaults".

If I were to use only "retry=3" would only enforce the 3 tries before I'm not allowed to attempt a password. If I do not specify a "remember=x" parameter, are no passwords remembered or are all passwords remembered?

veerain 02-09-2015 10:37 PM

See this site.

Or read man page of pam_cracklib.

adamp_oh 02-10-2015 07:04 AM

Insightful answer, thank you for the effort.

mijohnst 02-16-2015 08:38 PM

I'm just switching over from pam_passwdqc but this is what I've added to my systems. Hope it helps. I was was able to find a really good info at the redhat sit.

Code:

auth        required      pam_env.so
auth        required      pam_faillock.so preauth silent audit deny=3 even_deny_root unlock_time=3600 root_unlock_time=600
auth        sufficient    pam_unix.so nullok try_first_pass
auth        [default=die] pam_faillock.so authfail deny=3 unlock_time=604800 fail_interval=900
auth        sufficient    pam_faillock.so authsucc deny=3 unlock_time=604800 fail_interval=900
auth        requisite    pam_succeed_if.so uid >= 500 quiet
auth        required      pam_deny.so

account    required      pam_faillock.so
account    required      pam_unix.so
account    sufficient    pam_localuser.so
account    sufficient    pam_succeed_if.so uid < 500 quiet
account    required      pam_permit.so

password    required      pam_cracklib.so minlen=10 lcredit=1 ucredit=1 dcredit=1 ocredit=1 difok=4
password    sufficient    pam_unix.so sha512 shadow nullok try_first_pass use_authtok
password    required      pam_deny.so

session    optional      pam_keyinit.so revoke
session    required      pam_limits.so
session    optional      pam_oddjob_mkhomedir.so
session    [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session    required      pam_unix.so



All times are GMT -5. The time now is 02:52 AM.