Package: libpam-ccreds
Version: 10-2

With LDAP + ccreds set up on a laptop, I just discovered that cc_dump
report that the root password is also cached.  I believe this is a
waste (and a minor security issue), as the root password already is
stored in /etc/shadow.

Can libpam-ccreds be changed to not store the password for root, or
perhaps support an argument minimum_uid (like libpam-heimdal does), to
allow us to limit ccreds to uids >= 1000.

Happy hacking,
-- 
Petter Reinholdtsen



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to