Bugzilla – Full Text Bug Listing |
Summary: | AUDIT-1: libpwquality: review pam_pwquality not yet whitelisted in rpmlint | ||
---|---|---|---|
Product: | [openSUSE] openSUSE Tumbleweed | Reporter: | Matthias Gerstner <matthias.gerstner> |
Component: | Security | Assignee: | Matthias Gerstner <matthias.gerstner> |
Status: | RESOLVED FIXED | QA Contact: | E-mail List <qa-bugs> |
Severity: | Normal | ||
Priority: | P5 - None | CC: | jsegitz, malte.kraus, matthias.gerstner, meissner, os.gnome.maintainers |
Version: | Current | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
Whiteboard: | |||
Found By: | --- | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Bug Depends on: | |||
Bug Blocks: | 1150178 |
Description
Matthias Gerstner
2019-09-12 10:48:11 UTC
I will look into this. This is a small and simple PAM module that only acts in the passwd change context to verify the quality of passwords according to various configuration settings and dictionaries. The code looks sane and shouldn't have and issues. I didn't look too closely into what libpwquality itself does with the password. In the worst case it would leak the password somehow but I sure hope this is not the case. I submitted this PAM module to the whitelisting in rpmlint. It should hit Factory in a while. The whitelisting is by now in Factory, therefore I'm closing this bug as FIXED. |