<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with pam_chauthtok in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/problem-with-pam-chauthtok/m-p/3966341#M757667</link>
    <description>BTW,&lt;BR /&gt;&lt;BR /&gt;I did find&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1078256" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1078256&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;which seems to be a similar type of report ...&lt;BR /&gt;&lt;BR /&gt;Rob</description>
    <pubDate>Wed, 21 Mar 2007 14:30:33 GMT</pubDate>
    <dc:creator>Robert Currey</dc:creator>
    <dc:date>2007-03-21T14:30:33Z</dc:date>
    <item>
      <title>Problem with pam_chauthtok</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/problem-with-pam-chauthtok/m-p/3966340#M757666</link>
      <description>One of our customers is using pam_ldap (hp11i non-trusted) and has some password policies in effect.&lt;BR /&gt;&lt;BR /&gt;we called &lt;BR /&gt;    int result = pam_acct_mgmt(m_pam_h, PAM_DISALLOW_NULL_AUTHTOK);&lt;BR /&gt;and got the PAM_NEW_AUTHTOK_REQD&lt;BR /&gt;&lt;BR /&gt;We then call pam_chauthtok(m_pam_h, PAM_CHANGE_EXPIRED_AUTHTOK);&lt;BR /&gt;&lt;BR /&gt;and our log then gathers the following ...&lt;BR /&gt;(master) [21 Mar 18:32:18]: leader[7]: pam-login:PamConversationHandler num_msg=1&lt;BR /&gt;(master) [21 Mar 18:32:18]: leader[7]: pam-login:PamConversationHandler msg[0]: Old password:  (prompt w/o echo)&lt;BR /&gt;(master) [21 Mar 18:32:23]: leader[7]: pam-login:PamConversationHandler response=install10&lt;BR /&gt;(master) [21 Mar 18:32:23]: leader[7]: pam-login:PamConversationHandler num_msg=1&lt;BR /&gt;(master) [21 Mar 18:32:23]: leader[7]: pam-login:PamConversationHandler msg[0]: New password:  (prompt w/o echo)&lt;BR /&gt;(master) [21 Mar 18:32:24]: leader[7]: pam-login:PamConversationHandler response=aa&lt;BR /&gt;(master) [21 Mar 18:32:24]: leader[7]: pam-login:PamConversationHandler num_msg=1&lt;BR /&gt;(master) [21 Mar 18:32:24]: leader[7]: pam-login:PamConversationHandler msg[0]: Re-enter new password:  (prompt w/o echo)&lt;BR /&gt;(master) [21 Mar 18:32:26]: leader[7]: pam-login:PamConversationHandler response=aa&lt;BR /&gt;(master) [21 Mar 18:32:26]: leader[7]: pam-login:PamConversationHandler num_msg=1&lt;BR /&gt;(master) [21 Mar 18:32:26]: leader[7]: pam-login:PamConversationHandler msg[0]: Failed password policy checking&lt;BR /&gt;(master) [21 Mar 18:32:26]: leader[6]: pam-login: pam_chauthtok returned 0&lt;BR /&gt;&lt;BR /&gt;So ... the pam module sent the "Failed password policy checking" string for us to display, but then pam_chauthtok return PAM_SUCCESS (so as far as the caller of the API is concerned the AUTHTOK was successfully changed and updated).&lt;BR /&gt;&lt;BR /&gt;Seems pretty clear to me that pam_chauthtok() is returning an invalid result (probably as a result of a module having a pam_sm_chauthtok bug()?)&lt;BR /&gt;&lt;BR /&gt;I'll try to gather some additional info if needed:&lt;BR /&gt;which pam_ldap package version&lt;BR /&gt;which LDAP backend&lt;BR /&gt;how the password policies are specified&lt;BR /&gt;etc&lt;BR /&gt;&lt;BR /&gt;Let me know what other info I can gather if needed.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Rob&lt;BR /&gt;</description>
      <pubDate>Wed, 21 Mar 2007 14:25:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/problem-with-pam-chauthtok/m-p/3966340#M757666</guid>
      <dc:creator>Robert Currey</dc:creator>
      <dc:date>2007-03-21T14:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with pam_chauthtok</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/problem-with-pam-chauthtok/m-p/3966341#M757667</link>
      <description>BTW,&lt;BR /&gt;&lt;BR /&gt;I did find&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1078256" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1078256&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;which seems to be a similar type of report ...&lt;BR /&gt;&lt;BR /&gt;Rob</description>
      <pubDate>Wed, 21 Mar 2007 14:30:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/problem-with-pam-chauthtok/m-p/3966341#M757667</guid>
      <dc:creator>Robert Currey</dc:creator>
      <dc:date>2007-03-21T14:30:33Z</dc:date>
    </item>
  </channel>
</rss>

