[prev in list] [next in list] [prev in thread] [next in thread] 

List:       squirrelmail-plugins
Subject:    [SM-PLUGINS] change_pass plugin improvement needed
From:       Frantisek Hanzlik <franta () hanzlici ! cz>
Date:       2009-09-20 20:56:13
Message-ID: 4AB696ED.6020501 () hanzlici ! cz
[Download RAW message or body]

Hello,

on my system (Fedora 11 i386, squirrelmail-1.4.19, change_pass-3.0,
poppassd-1.8.5) "change_pass" plugin behaves incorrectly when user
pass new password, which is unsuitable for PAM subsystem.
"poppassd" daemon on that passwd respond like this:

500 PAM error: BAD PASSWORD: it is based on a dictionary word
500 PAM error: BAD PASSWORD: is too simple
200 Password changed, thank-you.

(i.e. PAM doesn't like it, but as poppassd daemon run as root, password
is changed - third line tell truly about it).

But change_pass plugin seems to test return code on first response line
(500) and inform user that "Password change was not successful!".

Second problem - what if I want respect PAM dissatisfaction with weakly
designed password (and want disabling that password change - i.e. simply
behavior, as if password change is done by non-root user) ? Maybe some
better response parsing with some option as OBEY_PAM_WARNINGS ;) in
plugins/change_pass/options.php can solve this, but I'm not programmer...

Regards, Franta Hanzlik

------------------------------------------------------------------------------
Come build with us! The BlackBerry&reg; Developer Conference in SF, CA
is the only developer event you need to attend this year. Jumpstart your
developing skills, take BlackBerry mobile applications to market and stay 
ahead of the curve. Join us from November 9&#45;12, 2009. Register now&#33;
http://p.sf.net/sfu/devconf
-----
squirrelmail-plugins mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-plugins@lists.sourceforge.net
List archives: http://news.gmane.org/gmane.mail.squirrelmail.plugins
List info (subscribe/unsubscribe/change options): \
https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic