*BSD News Article 30320


Return to BSD News archive

Path: sserve!newshost.anu.edu.au!harbinger.cc.monash.edu.au!bunyip.cc.uq.oz.au!munnari.oz.au!spool.mu.edu!sdd.hp.com!caen!usenet.coe.montana.edu!nate
From: nate@cs.montana.edu (Nate Williams)
Newsgroups: comp.os.386bsd.questions
Subject: Re: [FreeBSD-1.1] New users password problems.
Date: 14 May 1994 01:03:09 GMT
Organization: Computer Science, MSU, Bozeman MT, 59717
Lines: 28
Message-ID: <2r180d$hp3@pdq.coe.montana.edu>
References: <Cpp3H5.D6n@oea.hacktic.nl>
NNTP-Posting-Host: schizo.coe.montana.edu

In article <Cpp3H5.D6n@oea.hacktic.nl>,  <dan@oea.hacktic.nl> wrote:
>
>I installed FreeBSD-1.1 and added two new users using the dreaded vipw. I
>then used chpass to give one of them a passwd. Now I can login to the user
>account without a password but can not login to the one with a password. I
>also noticed that master.password contains the password in plain text form.
>Is this normal? Or is this due to a lack of crypt functionality?

This is bad.  Something is REALLY screwed up since FreeBSD doesn't have a
plain-text crypt function.  It's ALWAYS used some form of 'hiding' the plain
text password from the sys. ad.

This sounds like password wasn't used to add the password, but it was
hard-coded when you ran vipw.

Did you install the secure distribution from another site?  Try running passwd
again and make sure that passwd is used on that user.

By default FreeBSD *scrambles* the password entries, which is not as strong
as DES encryption but is exportable and is better than plain-text.


Nate
-- 
nate@bsd.coe.montana.edu     |  Still trying to find a good reason for
nate@cs.montana.edu          |  these 'computer' things.  Personally,
work #: (406) 994-4836       |  I don't think they'll catch on - 
home #: (406) 586-0579       |                            Don Hammerstrom