
Problematic pam-config

Closed this issue · 4 comments

Hi -

did you ever see this launch pad bug ? . I think this may still be a problem as I have just been bitten by the entries:

(account|auth|password) sufficient            

being added to the common-* files leaving my Ubuntu instance open to a user with any password as was reported on launch pad.

I'm wondering if it would be better to omit this auto-configuration as a security precaution for others?

Piers Harding.

No I didn't thanks for pointing out!

Actually I'm removing the debian directory out of the source tree since it is maintained by a debian developer now. I have contacted him to replace all sufficient with optional so it keeps current pam stack intact.

Thanks - can you point me to the debian maintained repository?

Piers Harding.