Any chance for Scalix to use cracklib for password checking?

Discuss the Scalix Server software

Moderators: ScalixSupport, admin

Beaujolais
Posts: 94
Joined: Sun Sep 03, 2006 2:47 pm
Location: Burlington, Ontario

Any chance for Scalix to use cracklib for password checking?

Postby Beaujolais » Mon Oct 01, 2007 6:35 pm

Is there a chance that future Scalix releases will use cracklib to check passwords?

Or is this available today perhaps? Did I miss it?

Today's rules for password complexity are quite limited (weak) IMHO.

Beaujolais
Posts: 94
Joined: Sun Sep 03, 2006 2:47 pm
Location: Burlington, Ontario

Postby Beaujolais » Mon Oct 01, 2007 9:44 pm

After some additional searching I see that scalix is using pam system.

- Is this standard system pam or some own implementation used internally for scalix?

- Which module in /var/opt/scalix/*/s/sys/pam.d/ is used for password changes through SWA?

If it is standard pam adding cracklib should not be that hard.

chris
Scalix Star
Scalix Star
Posts: 321
Joined: Mon May 09, 2005 2:56 pm
Location: Freiburg, Germany

Postby chris » Tue Oct 02, 2007 12:01 am

Hi Beaujolais,

I've never tried adding pam_cracklib, but it'd certainly be worth a try if you're feeling adventurous with a test system.

Scalix SWA is, in essence, an IMAP client. This it depends on the Remote Client Interface in Scalix. The relevant pam configuration is in /var/opt/scalix/*/s/sys/pam.d/ual.remote

You can try adding it in there - I don't have time to test this now myself, but I'd be curious to hear what you find.

Chris

Beaujolais
Posts: 94
Joined: Sun Sep 03, 2006 2:47 pm
Location: Burlington, Ontario

Postby Beaujolais » Tue Oct 02, 2007 3:36 pm

Chris, I've tried adding cracklib to ual.remote but it does not seem to work.


Return to “Scalix Server”



Who is online

Users browsing this forum: Google [Bot] and 5 guests

cron