hi, the option "minimum days before password change is allowed" in the shadow utils does not work. I have set the min days before pw change option to "100" (with "chage -m 100") but he user is still allowed to change his password with the passwd program. The tokens in the shadow password file are correct, but were not considered.
What do you get when you run "getent passwd <user>"? Does the encrypted password field contain an "x"? Does it work correctly if you replace instances of pam_pwdb.so in /etc/pam.d/passwd with pam_unix.so?
The encrypted password field contains an "x" with getent passwd <user> ! With the module pam_unix.so instead of pam_pwdb.so it does work correctly: (current) UNIX password: You must wait longer to change your password passwd: Authentication token manipulation error
The upcoming release uses pam_unix.so instead of pam_pwdb.so for everything by default, and pwdb is itself being phased out, so I'll tag this as resolved in Raw Hide.