[Bug 711770] Re: current pam setup ignores everything (for example: bad passwords, configuration problems)

2011-02-02 Thread Valentijn Sessink
"Ignoring everything, except success" is the security issue. I don't have anything against trying all modules, nor do I think that the "one succeeding module" is a security issue per se. But ignoring blatant errors, locked out users, wrong and/or expired passwords, that is a security issue. May

[Bug 711770] Re: current pam setup ignores everything (for example: bad passwords, configuration problems)

2011-02-02 Thread Steve Langasek
This is not a security issue. The default PAM stack is *deliberately* organized such that each module is tried in turn and any one succeeding authentication module is treated as a success for the whole stack. If this is not the site policy you want, then you should use pam-auth- update to change