"Daniel Richard G." <email address hidden> writes:
> Ah, thanks for clarifying, on both counts. So it's not that use_authtok
> was the wrong option to use after all.
Correct. use_authtok should not affect the handling of the current
password, only the new password. pam-krb5 incorrectly applied it to both.
In 4.0 and later, the current password handling is controlled by
{try,use,force}_first_pass only and use_authtok affects only the new
password in the password change group, which then works correctly with how
pam-auth-update works (and what Linux PAM says).
"Daniel Richard G." <email address hidden> writes:
> Ah, thanks for clarifying, on both counts. So it's not that use_authtok
> was the wrong option to use after all.
Correct. use_authtok should not affect the handling of the current force}_ first_pass only and use_authtok affects only the new
password, only the new password. pam-krb5 incorrectly applied it to both.
In 4.0 and later, the current password handling is controlled by
{try,use,
password in the password change group, which then works correctly with how
pam-auth-update works (and what Linux PAM says).
-- www.eyrie. org/~eagle/>
Russ Allbery (<email address hidden>) <http://