Comment 6 for bug 536930

Revision history for this message
Russ Allbery (rra-debian) wrote : Re: [Bug 536930] Re: Password changing fails when "krb5" pam-config is not first

"Daniel Richard G." <email address hidden> writes:

> Ah, thanks for clarifying, on both counts. So it's not that use_authtok
> was the wrong option to use after all.

Correct. use_authtok should not affect the handling of the current
password, only the new password. pam-krb5 incorrectly applied it to both.
In 4.0 and later, the current password handling is controlled by
{try,use,force}_first_pass only and use_authtok affects only the new
password in the password change group, which then works correctly with how
pam-auth-update works (and what Linux PAM says).

--
Russ Allbery (<email address hidden>) <http://www.eyrie.org/~eagle/>