System Administration
cancel
Showing results for 
Search instead for 
Did you mean: 

passwd aging and forcing passwd change doesn't work at all

arking1981
Frequent Advisor

passwd aging and forcing passwd change doesn't work at all

Hello,

I found the passwd aging and forcing passwd change at next login didn't work at all in my system.
My test was to execute command line like:
"passwd -r files -f -x 14 -n 7 student1"
Meaning: force student1 to establish a new password on the next login which will expire in 14 days and prohibit the user from changing the password until 7 days have transpired.

But when I login with student1 at next time, I was not asked to update the passwd.

I have done some search here and found no matching topic, so I post this question.
Can anyone provide some help?

Thanks in advance.

Regards
arking
Hello world...
11 REPLIES
Steven E. Protter
Exalted Contributor

Re: passwd aging and forcing passwd change doesn't work at all

Shalom,

What is on passwd -sa

What is in /etc/default/security

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Hakki Aydin Ucar
Honored Contributor

Re: passwd aging and forcing passwd change doesn't work at all

try this:
# passwd -n 0 -x 14

by the way; Which version of HP-UX ?
Hakki Aydin Ucar
Honored Contributor

Re: passwd aging and forcing passwd change doesn't work at all

Options:

-f Force the user to change the password on the next login
EXAMPLE: passwd -f username

-n Specify a minimum password life time (the password cannot be changed during this time)
EXAMPLE: passwd -n1 username

-x Specify a maximum password ((the password must be changed after this time and password aging may vary
between 1 and 158 days)
EXAMPLE: passwd -x158 username

-l Lock a password so the user cannot login
EXAMPLE: passwd -l username
Jose luis Martinez Esca
Occasional Advisor

Re: passwd aging and forcing passwd change doesn't work at all

hi arking

only one question are you using Trusted System, SMSE o no security policies in your system?

ch2
arking1981
Frequent Advisor

Re: passwd aging and forcing passwd change doesn't work at all

Hi,

Thanks all for your response.
The system is HP-UX 11i.
It isn't using a trusted system

Now the problem seems related with SSH login. When I used telnet to login, the passwd was requested to change because of expiry. But for SSH login, it didn't.

Is the SSH corrupted?
Maybe I need to re-install it?

Regards
arking
Hello world...
Ganesan R
Honored Contributor

Re: passwd aging and forcing passwd change doesn't work at all

Hi,

SSH login also should say password expired and ask the user to change the password. Because SSH and telnet is same as far as authentication is concern.

If the account is configured with password less login then ssh login may not work I hope.

What is the error you are getting when you login through ssh?
Best wishes,

Ganesh.
Matti_Kurkela
Honored Contributor

Re: passwd aging and forcing passwd change doesn't work at all

Which version of SSH?

I seem to recall that old versions had some problems in password aging support.

Get the latest version of SSH from software.hp.com for free. Read the release notes before installing: the newer versions of SSH have some patch requirements for some HP-UX versions.

MK
MK
arking1981
Frequent Advisor

Re: passwd aging and forcing passwd change doesn't work at all

Hi,

Re Ganesan R:
The error was no expiry nofication at the next login after enabling the "force passwd change at next login".
And can you explain what is "configured with password less login"? I don't understand it. Thanks.

Re Matti Kurkela:
Maybe the version is too old:
> what /usr/bin/ssh
/usr/bin/ssh:
HP92453-02A.11.00 HP-UX SYMBOLIC DEBUGGER (END.O ILP32) $Revision: 75.02

As we have other machines with "$OpenSSL A.00.09.07i" installed and it was ok.

If my version too old?
Thanks

Best regards,
arking
Hello world...
Dennis Handly
Acclaimed Contributor

Re: passwd aging and forcing passwd change doesn't work at all

>HP92453-02A.11.00 HP-UX SYMBOLIC DEBUGGER (END.O ILP32) $Revision: 75.02

This is the version of end.o, used with -g, useless.
arking1981
Frequent Advisor

Re: passwd aging and forcing passwd change doesn't work at all

Thanks all.
It's because the SSH installed too old
Hello world...
arking1981
Frequent Advisor

Re: passwd aging and forcing passwd change doesn't work at all

I have found a solution to this question as seen in the comments below.
Hello world...