[29447] in Kerberos
Re: password change after expiry
daemon@ATHENA.MIT.EDU (Russ Allbery)
Tue Mar 11 14:38:06 2008
To: kerberos@mit.edu
In-Reply-To: <fr5dmq$mg3$1@news.onet.pl> (Marcin N.'s message of "Tue\,
11 Mar 2008 08\:52\:06 +0100")
From: Russ Allbery <rra@stanford.edu>
Date: Tue, 11 Mar 2008 11:37:07 -0700
Message-ID: <871w6hw1ik.fsf@windlord.stanford.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Marcin N <nichu@nospam.onet.pl> writes:
> Oh yeah I forgot to write about it :/
>
> I'm using mit-krb5 on gentoo - it's on clients server is on debian
> (krb5-kdc and krb5-admin-server 1.4.4-7etch4) but probably will be on
> solaris
What PAM module are you using on Gentoo? I don't know which one they
ship. Mine should prompt you for a new password for an expired password.
You don't, however, say whether you're using console login or ssh. For
expired account password changes via ssh, you have to use
ChallengeResponseAuthentication. PasswordAuthentication doesn't have
sufficient interactivity in the protocol to handle the prompting.
--
Russ Allbery (rra@stanford.edu) <http://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos