What does '*' symbol in /etc/passwd means?

george jeffe at eniac.seas.upenn.edu
Thu Jun 6 15:11:22 AEST 1991


:I've heard the practice of replacing this field with an '*' as 'starring-out'
:the password, making it impossible for someone to login to that ID since the
:password encryption mechanism is guaranteed to fail.  I've routinely made
:this field "*LOCKED*" or "*NO LOGIN*"  to achieve the same purpose.

of interest.. no entry in the password field ( "*", null, random characters )
"locks" the account if the user has enabled no-password rlogin via a .rlogin
entry.  I suppose this is obvious, but I had to try it to find out.

In this case you can lock the user out by corrupting his home directory entry
as well as his password.

-based on ten minutes of exhaustive testing on a sun4.
--
-george            george at mech.seas.upenn.edu



More information about the Comp.unix.questions mailing list