Re: SHA512 passwords in shadow

2010-06-28 Thread DJ Lucas
On 06/28/2010 11:10 PM, DJ Lucas wrote: > On 06/28/2010 10:20 PM, Bruce Dubbs wrote: > >> We probably need to also mention: > >> # Note: If you use PAM, it is recommended to use a value consistent with >> # the PAM modules configuration. > >> Other opinions? > >>-- Bruce > > > Despite the

Re: SHA512 passwords in shadow

2010-06-28 Thread DJ Lucas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 06/28/2010 10:20 PM, Bruce Dubbs wrote: > We probably need to also mention: > > # Note: If you use PAM, it is recommended to use a value consistent with > # the PAM modules configuration. > > Other opinions? > >-- Bruce Despite the comment

Re: SHA512 passwords in shadow

2010-06-28 Thread Kevin White
On 6/28/2010 11:20 PM, Bruce Dubbs wrote: > I'm not sure I want to change it to SHA512 in the actual instruction, > but we might mention in the text that SHA256 and SHA256 are other options. > > We probably need to also mention: > > # Note: If you use PAM, it is recommended to use a value consisten

Re: SHA512 passwords in shadow

2010-06-28 Thread Bruce Dubbs
Kevin White wrote: > The sed command in the instructions for shadow (in both the 6.6 and SVN) > sets the password encryption to MD5. > > Just by modifying that sed, I changed it to SHA512, which is just one of > the options that should be more secure than MD5. Everything just worked > once I m

SHA512 passwords in shadow

2010-06-28 Thread Kevin White
The sed command in the instructions for shadow (in both the 6.6 and SVN) sets the password encryption to MD5. Just by modifying that sed, I changed it to SHA512, which is just one of the options that should be more secure than MD5. Everything just worked once I made that change. Would changin