SUMMARY - Enhanced Security and Passwords

From: J Bacher <jb_at_jbacher.com>
Date: Wed, 13 Dec 2000 16:33:54 -0600

Thanks to Frank Wortner and Ann Majeske.

PROBLEM

Changing the u_minlen in /etc/auth/system/default did not work to require
the password length requested. I was looking for an alternate
configuration parameter, file, etc. This behavior was different than 3.x
and 4.x using enhanced security.

SOLUTION

I had to change the u_minchosen field from 0 to the parameter I desired.



An important note from Frank:

"Note that changing the length puts you out of compliance with the DoD Orange
Book. The longer passwords are apparently *significantly more secure*, so
Tru64 defaults to requiring them."

An additional note from Ann:

"There was a requirement to allow different minimums for system generated
and user selected passwords. I believe that it was implemented
in the V5.0 timeframe. I don't know why, but the system
generated passwords got the existing field and a new one
was created for user selected passwords."
Received on Wed Dec 13 2000 - 22:25:39 NZDT

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:41 NZDT