Re: [OE-core] [PATCH 6/9] shadow: update 4.8.1 -> 4.9

2021-08-04 Thread Mark Hatle
On 8/4/21 1:13 PM, Khem Raj wrote: > > > On 8/4/21 3:12 AM, Alexander Kanavin wrote: >> Yes, plaintext passwords can no longer be there, which is a good thing >> I'd say? The hashed/salted passwords can still be provided through the >> same class, but this needs to be documented, and perhaps

Re: [OE-core] [PATCH 6/9] shadow: update 4.8.1 -> 4.9

2021-08-04 Thread Khem Raj
On 8/4/21 3:12 AM, Alexander Kanavin wrote: Yes, plaintext passwords can no longer be there, which is a good thing I'd say? The hashed/salted passwords can still be provided through the same class, but this needs to be documented, and perhaps tested too. Its perhaps fine to discourage plai

Re: [OE-core] [PATCH 6/9] shadow: update 4.8.1 -> 4.9

2021-08-04 Thread Alexander Kanavin
Yes, plaintext passwords can no longer be there, which is a good thing I'd say? The hashed/salted passwords can still be provided through the same class, but this needs to be documented, and perhaps tested too. Alex On Wed, 4 Aug 2021 at 10:39, Yi Zhao wrote: > > On 7/30/21 7:45 PM, Alexander K

Re: [OE-core] [PATCH 6/9] shadow: update 4.8.1 -> 4.9

2021-08-04 Thread Yi Zhao
On 7/30/21 7:45 PM, Alexander Kanavin wrote: Add a couple backports to fix builds. Drop 0002-Allow-for-setting-password-in-clear-text.patch; what it adds is horribly insecure and AB testing didn't reveal any regressions or use cases for it. Dropping this patch makes the password setting funct

[OE-core] [PATCH 6/9] shadow: update 4.8.1 -> 4.9

2021-07-30 Thread Alexander Kanavin
Add a couple backports to fix builds. Drop 0002-Allow-for-setting-password-in-clear-text.patch; what it adds is horribly insecure and AB testing didn't reveal any regressions or use cases for it. Drop /etc/default/ tweaks as files are no longer installed there. Drop manpage alternatives as manpa