Bug 129 - PAM with ssh authentication fails treat PAM_NEW_AUTHTOK_REQD properly
Summary: PAM with ssh authentication fails treat PAM_NEW_AUTHTOK_REQD properly
Status: CLOSED DUPLICATE of bug 423
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: sshd (show other bugs)
Version: -current
Hardware: UltraSPARC Solaris
: P2 normal
Assignee: Kevin Steves
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2002-02-28 05:43 AEDT by Bob Smith
Modified: 2004-04-14 12:24 AEST (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bob Smith 2002-02-28 05:43:09 AEDT
when using ssh's authentication against either pam_unix or pam_krb5 expired 
passwords are not treated properly.

with pam_unix: sshd: users are not prompted to change their password and can 
login.

with pam_unix: scp: users are not prompted to change their password and can 
transfer files.

with pam_krb5: sshd: users are not prompted to change their password and cannot 
login.

with pam_krb5: scp: users are not prompted to change their password and can 
transfer files.


currently the only way to get expired passwords treated correctly by sshd is to 
use the system's login routine with pam_unix. there is no way to get scp to 
behave properly.
Comment 1 Kevin Steves 2002-03-31 05:44:14 AEST
i will look at this.
Comment 2 Kevin Steves 2002-03-31 16:37:15 AEST
solaris 8 + openssh3.1p1; something about doing a PAM operation with euid 0?
has this ever worked on solaris?

$ ssh solen
Warning: Your password has expired, please change it now
Enter login password: 
removing root credentials would break the rpc services that
use secure rpc on this host!
root may use keylogout -f to do this (at your own risk)!
Connection to 172.31.1.203 closed by remote host.
Connection to 172.31.1.203 closed.
Comment 3 Damien Miller 2003-01-07 17:18:42 AEDT
This will be fixed up by whatever ends up fixing Bug #423

*** This bug has been marked as a duplicate of 423 ***
Comment 4 Damien Miller 2004-04-14 12:24:18 AEST
Mass change of RESOLVED bugs to CLOSED