Folks, folks, folks.

While I certainly agree that the "best" option is to keep the dictionary
checking on, this is not what Brad has asked for.  It is certainly a
good idea to let him know of the vulnerabilities of taking the this
route, but let's try to help him solve the question he put forth, lest
we start to sound like tech support from a certain unnamed Redmond based
company.... ("You don't want to do that, do it our way instead.")

To Brad:

Is there a line in /etc/pam.d/passwd that looks something like:

password   required /lib/security/pam_cracklib.so retry=3

?
I believe that may be the culprit.  To echo what others have said, this
is not necessarily the best option though if the users have no shell
access it MIGHT be ok.  If you go this route, definitely turn off shell
access for unnecessary users and turn off telnet entirely.  If you need
to connect to it remotely, use a secure method such as openssh
(http://www.openssh.com).


--
"In my opinion, Macs are really just toys..." - An anonymous UNH
professor

Cole Tuininga
Network Admin
Code Energy, Inc
[EMAIL PROTECTED]
(603) 766-2208

**********************************************************
To unsubscribe from this list, send mail to
[EMAIL PROTECTED] with the following text in the
*body* (*not* the subject line) of the letter:
unsubscribe gnhlug
**********************************************************

Reply via email to