I don't think this should be in main without the appropriate pam-auth- update hooks to use it correctly. As it turns out, this is already a Debian bug: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=566718
Beyond that, it clears passwords, correctly processes pam password attempts, correctly opens/creates with a private mode, and no buffer overflows or other obvious stuff jumps out at me. If the above bug is solved, I think this would be a supportable and useful addition to main. ** Bug watch added: Debian Bug tracker #566718 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=566718 ** Changed in: libpam-ccreds (Ubuntu) Assignee: Kees Cook (kees) => (unassigned) ** Changed in: libpam-ccreds (Ubuntu) Status: New => Incomplete -- [MIR] libpam-ccreds https://bugs.launchpad.net/bugs/523354 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs