Package: libpam-ldapd
Version: 0.9.4-3
Severity: important

Dear Maintainer,

In a typical Debian installation, protection against obvious passwords
is implemented by the "obscure" option in the pam_unix module. When the
libpam-ldapd is installed, the /etc/pam.d/common-password contains:

password        [success=2 default=ignore]      pam_unix.so obscure sha512
password        [success=1 default=ignore]      pam_ldap.so minimum_uid=1000 
try_first_pass

and so no "bad password" checks are applied for LDAP users.

Suggested fix: make the pam_pwquality module either a pre-requisite or
recommended dependency for pam_ldapd, and document this limitation in a
README.Debian file.


*** Reporter, please consider answering these questions, where appropriate ***

   * What led up to the situation?
   * What exactly did you do (or not do) that was effective (or
     ineffective)?
   * What was the outcome of this action?
   * What outcome did you expect instead?

*** End of the template - remove these template lines ***


-- System Information:
Debian Release: 8.3
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.16.0-4-amd64 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages libpam-ldapd depends on:
ii  libc6              2.19-18+deb8u3
ii  libpam-runtime     1.1.8-3.1+deb8u1
ii  libpam0g           1.1.8-3.1+deb8u1
ii  multiarch-support  2.19-18+deb8u3
ii  nslcd [nslcd-2]    0.9.4-3

libpam-ldapd recommends no packages.

libpam-ldapd suggests no packages.

-- no debconf information

Reply via email to