man: don't suggest using pam_unix.so's use_authtok switch
authorLennart Poettering <lennart@poettering.net>
Wed, 17 Jan 2024 22:41:14 +0000 (23:41 +0100)
committerLuca Boccassi <luca.boccassi@gmail.com>
Wed, 17 Jan 2024 23:59:05 +0000 (23:59 +0000)
commit75f8b0fe70002176b505010d633d95628eb8c40a
tree19433e7acb54bc97ac1e610ddf260de06e45abc5
parentb9e2d83b75d078143c7ccac3b3070f420b342315
man: don't suggest using pam_unix.so's use_authtok switch

Our dumbed down example PAM stacks do not contain cracklib/pwq modules,
hence using use_authtok on the pam_unix.so password change stack won't
work, because it has the effect that pam_unix.so never asks for a
password on its own, expecting the cracklib/pwq modules to have
queried/validated them beforehand.

I noticed this issue because of #30969: Debian's PAM setup suffers by
the same issue – even though they don't actually use our suggested PAM
fragments at all.

See: #30969
factory/etc/pam.d/system-auth
man/pam_systemd.xml
man/pam_systemd_home.xml