Bug 819 - patch to add kerberos password-changing
Summary: patch to add kerberos password-changing
Status: CLOSED WONTFIX
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: Kerberos support (show other bugs)
Version: 3.8p1
Hardware: UltraSPARC Solaris
: P2 enhancement
Assignee: OpenSSH Bugzilla mailing list
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-03-26 07:51 AEDT by Buck Huppmann
Modified: 2016-08-02 10:41 AEST (History)
1 user (show)

See Also:


Attachments
referenced patch (4.94 KB, patch)
2004-03-26 07:52 AEDT, Buck Huppmann
no flags Details | Diff
updated patch (5.52 KB, patch)
2004-03-31 01:09 AEST, Buck Huppmann
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Buck Huppmann 2004-03-26 07:51:49 AEDT
here's a patch that invokes kpasswd in the event the KDC fails to authenticate
a user's kerberos-5 password b/c it's expired: it attempts to get a ticket for
kadmin/changepw and, if that works, dumps the user into kpasswd instead of
passwd

note that i don't consider myself security-cognizant enough to have thought
through all the ramifications of this and whether it might not be opening up
holes. nevertheless, i'm submitting it in case it's not completely demented,
so you all can figure out whether to implement it and, hopefully, code it up
so it doesn't have the bugs my patch undoubtedly does
Comment 1 Buck Huppmann 2004-03-26 07:52:59 AEDT
Created attachment 576 [details]
referenced patch
Comment 2 Buck Huppmann 2004-03-31 01:09:33 AEST
Created attachment 581 [details]
updated patch

sorry. slight fix to work with MIT krb5 libraries. of course, MIT's kpasswd
isn't working when it gets exec-ed (i have the same problem as this guy:
http://mailman.mit.edu/pipermail/kerberos/2003-October/003990.html
), but, anyway, . . .
Comment 3 Damien Miller 2015-11-13 14:21:52 AEDT
This can be done using PAM kbd-int without server modifications. I don't think we want to implement it again in the server.
Comment 4 Damien Miller 2016-08-02 10:41:22 AEST
Close all resolved bugs after 7.3p1 release