<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lame password checking. in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795888#M80949</link>
    <description>Answered my own question.&lt;BR /&gt;&lt;BR /&gt;Found a PAM module called pam_passwdqc (Google search for it.. even supports HP-UX) that does exactly what I want!&lt;BR /&gt;&lt;BR /&gt;FYI.. u_genchar etc. controlls wether or not the user can pick that option (i.e. "Generate character password", "Generate prononcable", etc.)&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Wed, 28 Aug 2002 16:39:10 GMT</pubDate>
    <dc:creator>Eric Ladner</dc:creator>
    <dc:date>2002-08-28T16:39:10Z</dc:date>
    <item>
      <title>Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795880#M80941</link>
      <description />
      <pubDate>Wed, 28 Aug 2002 13:17:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795880#M80941</guid>
      <dc:creator>Eric Ladner</dc:creator>
      <dc:date>2002-08-28T13:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795881#M80942</link>
      <description>Oops.. hit enter too soon.&lt;BR /&gt;&lt;BR /&gt;Is there a way to strengthen the password rules used at the time a user is picking a new password?  I'm using HP-UX 11.0 on Trusted System.  I have been searching the docs and the forum for quite a while to find some mention of where this actually occurs and if there is a way to substitute a new program to accept or reject user picked passwords.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Eric</description>
      <pubDate>Wed, 28 Aug 2002 13:19:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795881#M80942</guid>
      <dc:creator>Eric Ladner</dc:creator>
      <dc:date>2002-08-28T13:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795882#M80943</link>
      <description>Hi Eric,&lt;BR /&gt;&lt;BR /&gt; AFAIK, the only way to do this would be to write a wrapper script around the passwd command that will do the checking &amp;amp; accept/reject the supplied PW before it's actually passed to passwd.&lt;BR /&gt;&lt;BR /&gt;Search the forum, there have been several threads on this subject in the last 6 mos or so.&lt;BR /&gt;&lt;BR /&gt;Rgds,&lt;BR /&gt;Jeff</description>
      <pubDate>Wed, 28 Aug 2002 13:27:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795882#M80943</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2002-08-28T13:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795883#M80944</link>
      <description>In lieu of anything better my company run annual security CBT courses that encourage staff to use better passwords - everyone gets has to complete a quiz at the end and are made to redo the course if they fail - your auditors may be aware of such training.&lt;BR /&gt;&lt;BR /&gt;Also I occasionally take a look through the bad login attempts with lastb command as you can often locate any users here that use simple passwords as they will invariablly use a password as their login by mistake at some point. You can then try and work out who and issue a friendly reminder.</description>
      <pubDate>Wed, 28 Aug 2002 14:05:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795883#M80944</guid>
      <dc:creator>Nick Wickens</dc:creator>
      <dc:date>2002-08-28T14:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795884#M80945</link>
      <description>Does anybody have any information on a way to do this with PAM?  I assume that one could write a 'password' routine that does the necessary stuff, I just have almost no experience with PAM coding. &lt;BR /&gt;&lt;BR /&gt;Any examples out there?&lt;BR /&gt;&lt;BR /&gt;Eric</description>
      <pubDate>Wed, 28 Aug 2002 14:13:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795884#M80945</guid>
      <dc:creator>Eric Ladner</dc:creator>
      <dc:date>2002-08-28T14:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795885#M80946</link>
      <description>What requirements do you have for passwd security?&lt;BR /&gt;&lt;BR /&gt;This is probably undocumented, but have a look at editing the file &lt;BR /&gt;&lt;BR /&gt;/tcb/files/auth/system/default &lt;BR /&gt;&lt;BR /&gt;- specifically the line that reads:&lt;BR /&gt;&lt;BR /&gt;:u_restrict:u_nullpw@:u_genchars@:u_genletters:&lt;BR /&gt;I can't remember what combination there is, but you can specify minimum length, min number of letters, minimum number of numbers, and even requires non-char, non-int value (such as an "_" or a ":").&lt;BR /&gt;&lt;BR /&gt;Also, you may want to download Crack! or John the Ripper, which are password cracking tools, and running them once a month with a script that emails the offensive... I mean offending ;-) user that his password sux and he needs to change it - but that's my BOFH side talking.&lt;BR /&gt;&lt;BR /&gt;Cheers!&lt;BR /&gt;James</description>
      <pubDate>Wed, 28 Aug 2002 15:00:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795885#M80946</guid>
      <dc:creator>James Beamish-White</dc:creator>
      <dc:date>2002-08-28T15:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795886#M80947</link>
      <description>Oh, and you may want to play with going into SAM -&amp;gt; Auditing and Security -&amp;gt; System Security Policies -&amp;gt; Password Format Policies and removing the "System Generates Pronounceable", "System Generates Character" and "System Generates Letters Only" selections. This may affect user specified as well.&lt;BR /&gt;&lt;BR /&gt;Cheers!&lt;BR /&gt;James</description>
      <pubDate>Wed, 28 Aug 2002 15:02:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795886#M80947</guid>
      <dc:creator>James Beamish-White</dc:creator>
      <dc:date>2002-08-28T15:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795887#M80948</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;The following doc (along with the man page for default(4) and prpwd(4)) explains the entries found in the system/default file -&amp;gt; KBRC00008662.&lt;BR /&gt;&lt;BR /&gt;Password triviality checks for the following: login names or circular shifts of login names, palindromes or any word recognised by spell.&lt;BR /&gt;&lt;BR /&gt;Unfortunately the standard spell dictionary is of benefit for password checking as passwords must contain at least one non-alpha character.  It is therefore necessary to create a specialist dictionary containing all the permutations that you wish to check for, ie replacing all the letter 'i's with 1's and similar substitutions.&lt;BR /&gt;&lt;BR /&gt;I'd also suggest you check the man page for security (check docs.hp.com as it is currently only documented at 11i I believe) as there are some features that could be useful (if you have the latest pam patch)&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;Darren.&lt;BR /&gt;</description>
      <pubDate>Wed, 28 Aug 2002 15:52:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795887#M80948</guid>
      <dc:creator>Darren Prior</dc:creator>
      <dc:date>2002-08-28T15:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795888#M80949</link>
      <description>Answered my own question.&lt;BR /&gt;&lt;BR /&gt;Found a PAM module called pam_passwdqc (Google search for it.. even supports HP-UX) that does exactly what I want!&lt;BR /&gt;&lt;BR /&gt;FYI.. u_genchar etc. controlls wether or not the user can pick that option (i.e. "Generate character password", "Generate prononcable", etc.)&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 28 Aug 2002 16:39:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795888#M80949</guid>
      <dc:creator>Eric Ladner</dc:creator>
      <dc:date>2002-08-28T16:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795889#M80950</link>
      <description>Check patch PHCO_24390, which states:&lt;BR /&gt;&lt;BR /&gt;A site's security policies sometimes require new passwords&lt;BR /&gt;to contain specific numbers or types of characters, such as&lt;BR /&gt;at least two digits and at least one special character.&lt;BR /&gt;Resolution:&lt;BR /&gt;In addition to the standard password requirements,&lt;BR /&gt;optional entries in the file /etc/default/security specify&lt;BR /&gt;the minimum number of required characters of each type&lt;BR /&gt;(upper case characters, lower case characters, digits&lt;BR /&gt;and special characters) in a new password.&lt;BR /&gt;PASSWORD_MIN_UPPER_CASE_CHARS=N&lt;BR /&gt;PASSWORD_MIN_LOWER_CASE_CHARS=N&lt;BR /&gt;PASSWORD_MIN_DIGIT_CHARS=N&lt;BR /&gt;PASSWORD_MIN_SPECIAL_CHARS=N&lt;BR /&gt;The default value for N is 0.  These parameters have&lt;BR /&gt;effect only when a password is changed.  On untrusted&lt;BR /&gt;systems, these parameters do not apply to the root user.&lt;BR /&gt;The file /etc/default/security should be owned by root and&lt;BR /&gt;have 0644 permissions.&lt;BR /&gt;As an example, to require passwords at least 8 characters&lt;BR /&gt;long, composed of at least 5 upper case characters, 2&lt;BR /&gt;lower case characters and a digit, include the following&lt;BR /&gt;lines in /etc/default/security, as specified above:&lt;BR /&gt;PASSWORD_MIN_UPPER_CASE_CHARS=5&lt;BR /&gt;PASSWORD_MIN_LOWER_CASE_CHARS=2&lt;BR /&gt;PASSWORD_MIN_DIGIT_CHARS=1&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 01 Sep 2002 08:23:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795889#M80950</guid>
      <dc:creator>doug hosking</dc:creator>
      <dc:date>2002-09-01T08:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795890#M80951</link>
      <description>Eric,&lt;BR /&gt;&lt;BR /&gt;Have you thought about LDAP login?&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Sun, 01 Sep 2002 10:54:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795890#M80951</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2002-09-01T10:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Lame password checking.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795891#M80952</link>
      <description>Thanks Doug!  Exactly what I was looking for.  &lt;BR /&gt;&lt;BR /&gt;Harry, I'm currently looking at LDAP-UX integration with Active Directory which would remove the password issue for me totally.  I have to get the NT guys to do some stuff first, unfortunately.. &lt;BR /&gt;&lt;BR /&gt;Thanks for all the great info!&lt;BR /&gt;&lt;BR /&gt;Eric</description>
      <pubDate>Tue, 03 Sep 2002 13:27:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lame-password-checking/m-p/2795891#M80952</guid>
      <dc:creator>Eric Ladner</dc:creator>
      <dc:date>2002-09-03T13:27:21Z</dc:date>
    </item>
  </channel>
</rss>

