Patrick Weemeeuw writes: > I would propose to go for shadow for 1.2. > In the mean time, I will try to make a few applications PAM-aware, > to wet my feet and to gain some insight about how simple or complex > things are. After all, it's not a black or white thing, but we can > PAMify application by application.
Good decision. If I understand you correctly, we can set PAM to authenticate via shadow password only and deploy it in a piece-wise fashion. Then, once we have it deployed fully, we can start to introduce additional methods of validation. Thanks Bruce