Re: [Freeipa-users] Password requirements too stringent

2012-09-19 Thread Tim Hildred
- Original Message - > From: "Petr Spacek" > To: freeipa-users@redhat.com > Sent: Wednesday, September 19, 2012 9:56:21 PM > Subject: Re: [Freeipa-users] Password requirements too stringent > > On 09/19/2012 01:32 PM, Dmitri Pal wrote: > > On 09/19/2012 02:56

Re: [Freeipa-users] Password requirements too stringent

2012-09-19 Thread Petr Spacek
On 09/19/2012 01:32 PM, Dmitri Pal wrote: On 09/19/2012 02:56 AM, Jakub Hrozek wrote: On Tue, Sep 18, 2012 at 09:43:48PM -0400, Tim Hildred wrote: So, commenting out: passwordrequisite pam_cracklib.so try_first_pass retry=3 type= dcredit=-1 ucredit=-1 ocredit=-1 lcredit=0 minlen=8 Cau

Re: [Freeipa-users] Password requirements too stringent

2012-09-19 Thread Dmitri Pal
On 09/19/2012 02:56 AM, Jakub Hrozek wrote: > On Tue, Sep 18, 2012 at 09:43:48PM -0400, Tim Hildred wrote: >> So, commenting out: >> passwordrequisite pam_cracklib.so try_first_pass retry=3 type= >> dcredit=-1 ucredit=-1 ocredit=-1 lcredit=0 minlen=8 >> >> Caused users updating their pass

Re: [Freeipa-users] Password requirements too stringent

2012-09-19 Thread Tim Hildred
;Jakub Hrozek" > To: "Tim Hildred" > Cc: freeipa-users@redhat.com > Sent: Wednesday, September 19, 2012 4:56:42 PM > Subject: Re: [Freeipa-users] Password requirements too stringent > > On Tue, Sep 18, 2012 at 09:43:48PM -0400, Tim Hildred wrote: > > So, comment

Re: [Freeipa-users] Password requirements too stringent

2012-09-19 Thread Jakub Hrozek
On Tue, Sep 18, 2012 at 09:43:48PM -0400, Tim Hildred wrote: > So, commenting out: > passwordrequisite pam_cracklib.so try_first_pass retry=3 type= > dcredit=-1 ucredit=-1 ocredit=-1 lcredit=0 minlen=8 > > Caused users updating their passwords using ssh to get: > > [ykatabam@ykatabam ~]

Re: [Freeipa-users] Password requirements too stringent

2012-09-18 Thread Tim Hildred
+61 4 666 25242 IRC: thildred - Original Message - > From: "Jakub Hrozek" > To: freeipa-users@redhat.com > Sent: Tuesday, September 18, 2012 5:29:12 PM > Subject: Re: [Freeipa-users] Password requirements too stringent > > On Tue, Sep 18, 2012 at 02:57:49AM +

Re: [Freeipa-users] Password requirements too stringent

2012-09-18 Thread Jakub Hrozek
On Tue, Sep 18, 2012 at 02:57:49AM +, JR Aquino wrote: > > On Sep 17, 2012, at 7:53 PM, Tim Hildred wrote: > > > JR > > > > I had that line. I commented it out. Thank you. > > > > Now, what do I have to restart? > > I believe it should take effect in real time, but you may need to test to

Re: [Freeipa-users] Password requirements too stringent

2012-09-17 Thread JR Aquino
gt; From: "JR Aquino" >> To: "Tim Hildred" >> Cc: "freeipa-users" >> Sent: Tuesday, September 18, 2012 12:37:48 PM >> Subject: Re: [Freeipa-users] Password requirements too stringent >> >> Tim, please check your /etc/pam.d/system-

Re: [Freeipa-users] Password requirements too stringent

2012-09-17 Thread Tim Hildred
- > From: "JR Aquino" > To: "Tim Hildred" > Cc: "freeipa-users" > Sent: Tuesday, September 18, 2012 12:37:48 PM > Subject: Re: [Freeipa-users] Password requirements too stringent > > Tim, please check your /etc/pam.d/system-auth with the

Re: [Freeipa-users] Password requirements too stringent

2012-09-17 Thread JR Aquino
Tim, please check your /etc/pam.d/system-auth with the password block. If you see passwordrequisite pam_cracklib.so, then this is why you are having a problem. $ man pam_cracklib It is a local security library for enforcing strong password practices from the unix cli. ProTip: If you

Re: [Freeipa-users] Password requirements too stringent

2012-09-17 Thread Steven Jones
Maybe its the local system having requirements and not IPA? In my secure logs I see pam is quering first locally and then the sss daemonmaybe its failing you on the default rh setup of the OS? regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064