Re: Will SSH ever support password aging?

From: Bruno Wolff III (bruno_at_cerberus.csd.uwm.edu)
Date: 07/29/04


Date: 29 Jul 2004 13:41:10 GMT

In article <358db3cc.0407290525.56013994@posting.google.com>, Tonij wrote:
> It seems like this has been a problem forever; with telnet turned off
> and SSH as the only means of authenticating to my Solaris systems I
> cannot use password aging because the user is never prompted to change
> their password. Same thing with using passwd -df to force a change on
> first login.
>
> Will SSH *ever* support this? Currently using OpenSSH_3.8p1
>
> Are there any known work arounds for this? As it stands now I either
> have to turn off password aging and fight off the auditors, or be
> bothered with endless "can you reset my password" requests.

There is an ssh pam module. This should allow you to force password changes
if stacked with another module that checks for the password age.



Relevant Pages

  • [Summary]: SSH With Password Aging
    ... Subject: SSH With Password Aging ... We need to do perform some security configuration on our Solaris boxes ...
    (SunManagers)
  • Will SSH ever support password aging?
    ... and SSH as the only means of authenticating to my Solaris systems I ... cannot use password aging because the user is never prompted to change ... Will SSH *ever* support this? ...
    (comp.security.ssh)
  • ssh doesnt care about password aging
    ... Password aging is working when a user connects the machine with e. ... telnet, he/ she gets a warning when the password is about to expire, and ... But, ssh doesn't care about this, there is no warning abt. ... Harald Husemann ...
    (SunManagers)
  • Re: Getting password expiration date
    ... > We are using password aging on our HP-UX 11.11 system, ... versions of ssh and your patch levels on the system too, ...
    (comp.sys.hp.hpux)
  • Getting password expiration date
    ... We are using password aging on our HP-UX 11.11 system, ... recently been told that if a user goes into the system using SSH then ... can set up a script to email folks to warn them if so. ...
    (comp.sys.hp.hpux)