Right, mystery solved. I did not realise that passwd allows root to set the user's password to anything, even if the cracklib checks fail.
If I instead run 'sudo -u testuser passwd' then I am unable to set a weak password. Sorry for the noise. -- Sam Morris <s...@robots.org.uk> -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org