Subject: Re: /etc/passwd.conf
To: Todd Vierling <tv@pobox.com>
From: Sean Davis <dive@endersgame.net>
List: tech-security
Date: 08/05/2003 16:41:16
On Tue, Aug 05, 2003 at 11:19:36AM -0400, Todd Vierling wrote:
> On Tue, 5 Aug 2003, Jun-ichiro itojun Hagino wrote:
>
> : given that DES is crackable in 3 seconds, i would like to propose the
> : following change. you can still use DES password entries, it only
> : affects newly-created entries (like by passwd(1)). what do people
> : think? (ypcipher is kept to "old" for backward compat)
>
> This was brought up some time ago. The result was that the default is
> selectable in sysinst, and the copy in src/etc/passwd.conf is intentionally
> left commented out.
>
> Rather than changing src/etc/passwd.conf, which will be blown away by
> sysinst, you probably want to add a Blowfish option to sysinst.
IIRC, sysinst in -current has a blowfish option. I picked it when installing
-current on an Alpha recently.
-Sean
--
/~\ The ASCII
\ / Ribbon Campaign Sean Davis
X Against HTML aka dive
/ \ Email!