即使使用enforce_for_root选项,pam_cracklib也不要为根执行difok

发布于 2025-01-31 17:51:50 字数 296 浏览 3 评论 0 原文

我尝试为root执行difok = 7,但无法使它起作用。到现在为止,我尝试了每种组合,但它无法正常工作。我找不到有关此问题的任何信息。

PAM_CRACKLIB的这种正常状态不是针对root强制执行的difok = 7吗?

这是我正在使用的配置:密码必需pam_pwquality.so retry = 3 difok = 7 minlen = 10 ucredit = -1 dcredit = -1 maxrepeat = 3 refferend_username enforce_for_for_for_root

I tried enforcing difok=7 for root but can't get it to work. By now I tried every combination and it's just not working. I can't find any information in the manpage about this problem.

Is this normal that pam_cracklib is not enforcing difok=7 for root?

This is the configuration I am using: password requisite pam_pwquality.so retry=3 difok=7 minlen=10 ucredit=-1 dcredit=-1 maxrepeat=3 reject_username enforce_for_root

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(2

你在看孤独的风景 2025-02-07 17:51:50

Possible duplicate of https://unix.stackexchange.com/questions/239002/why-roots-password-change-doesnt-require-old-password.
In short: When you change the password for root it does not check for the old password, because this check would be pointless as it adds no additional security.

落日海湾 2025-02-07 17:51:50

在手册( man pam_pwquality.so )中,关于 enforce_by_root 选项有关于这一点的注释。

enforce_for_root

即使用户,模块也将在失败的检查上返回错误
更改密码是根。默认情况下,此选项已关闭
意味着仅打印有关支票失败的消息,但是
root可以还是可以更改密码。 请注意,不问root
对于旧密码,因此比较了新旧的检查
密码未执行。

这意味着检查将旧密码与新密码进行比较(在我们的情况下 difok )将被忽略。

in the manual (man pam_pwquality.so), there is a note about this point for the enforce_by_root option.

enforce_for_root

The module will return error on failed check even if the user
changing the password is root. This option is off by default which
means that just the message about the failed check is printed but
root can change the password anyway.Note that root is not asked
for an old password so the checks that compare the old and new
password are not performed.

which means that check that compare the old password with the new one (difok in our case) will be ignored.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文