Bug 229204
Summary: | Confusing information in passwd(5) and shadow(5) | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Tomas Mraz <tmraz> |
Component: | shadow-utils | Assignee: | Peter Vrabec <pvrabec> |
Status: | CLOSED INSUFFICIENT_DATA | QA Contact: | David Lawrence <dkl> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | rawhide | CC: | mitr, triage |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | bzcl34nup | ||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2008-05-07 01:12:13 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Tomas Mraz
2007-02-19 15:50:19 UTC
Please add the following information as well: - If the encrypted password, whether in /etc/passwd or in /etc/shadow, is an empty string, login is allowed without even asking for a password. Note that this functionality may be intentionally disabled in applications, or configurable (for example using the "nullok" or "nonull" arguments to pam_unix.so). - If the encrypted password in /etc/passwd is "*NP*" (without the quotes), the shadow record should be obtained from a NIS+ server. - If the "date of last password change" is 0, the password is considered to be expired (as if "days after which password must be changed" have already elapsed). In this case, "days after which password must be changed", "days after password expires that account is disabled" and "days since Jan 1 1970 that account is disabled" are ignored. [This sounds bad, the fields probably should have some short labels in the man page - e.g. those from <shadow.h>.] The following is currently pending discussion on pam-list, currently it is only partially true: - If the encrypted password, whether in /etc/passwd or in /etc/shadow, is "*", login is not allowed and the password can not be changed to any other value even by the root user, other than by editing /etc/passwd manually. This is used for system user accounts used e.g. for running daemons with restricted privileges. Please ignore the "*" paragraph, the PAM developers have decided to remove the feature. passwd(5) man page is fixed in man-pages-2.43-8.fc7. shadow(5) is part of shadow-utils. Based on the date this bug was created, it appears to have been reported against rawhide during the development of a Fedora release that is no longer maintained. In order to refocus our efforts as a project we are flagging all of the open bugs for releases which are no longer maintained. If this bug remains in NEEDINFO thirty (30) days from now, we will automatically close it. If you can reproduce this bug in a maintained Fedora version (7, 8, or rawhide), please change this bug to the respective version and change the status to ASSIGNED. (If you're unable to change the bug's version or status, add a comment to the bug and someone will change it for you.) Thanks for your help, and we apologize again that we haven't handled these issues to this point. The process we're following is outlined here: http://fedoraproject.org/wiki/BugZappers/F9CleanUp We will be following the process here: http://fedoraproject.org/wiki/BugZappers/HouseKeeping to ensure this doesn't happen again. This bug has been in NEEDINFO for more than 30 days since feedback was first requested. As a result we are closing it. If you can reproduce this bug in the future against a maintained Fedora version please feel free to reopen it against that version. The process we're following is outlined here: http://fedoraproject.org/wiki/BugZappers/F9CleanUp |