password aging

Ian F. Darwin ian at utcs.UUCP
Fri Jul 19 05:47:37 AEST 1985


In article <527 at dicomed.UUCP> salmi at dicomed.UUCP (John Salmi) writes:
>I understand that SysV offers a password aging scheme.  Does 4.x BSD support
>anything similar?  If no, has anyone done a hack to allow password aging?

I presume the reason that you're interested is to make your system
more secure. Some forms of password again can instead make it less so.
Before you copy the System V password aging stuff to 4BSD, I
recommend that you read the only significant discussion of
the topic that I'm aware of. It's contained in the following
paper in the AT&T Bell Labs Tech Journal.

%A F. T. Grampp
%A R. H. Morris
%T UNIX Operating System Security
%J BLTJ
%V 63
%N 8
%D October, 1984
%P 1649
%X Computing systems that are easy to access and that facilitate communication
with other systems are by their nature difficult to secure. Most often,
though, the level of security that is actually achieved is far below what it could
be. This is due to many factors, the most important of which are the
knowledge and attitudes of the administrators and users of such systems. We discuss
here some of the security hazards of the UNIX operating system, and we
suggest ways to protect against them, in the hope that an educated community
of users will lead to a level of protection that is stronger, but far more
importantly, that represents a reasonable and thoughtful balance between
security and ease of use of the system. We will not construct parallel examples
for other systems, but we encourage readers to do so for themselves.''



More information about the Comp.unix mailing list