Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.devel > #106816 > unrolled thread

need we support unshadowed passwords from the installer

Started bynick black <dankamongmen@gmail.com>
First post2023-01-14 03:20 +0100
Last post2023-01-15 20:10 +0100
Articles 8 — 5 participants

Back to article view | Back to linux.debian.devel


Contents

  need we support unshadowed passwords from the installer nick black <dankamongmen@gmail.com> - 2023-01-14 03:20 +0100
    Re: need we support unshadowed passwords from the installer Marc Haber <mh+debian-devel@zugschlus.de> - 2023-01-14 10:00 +0100
      Re: need we support unshadowed passwords from the installer nick black <dankamongmen@gmail.com> - 2023-01-14 15:20 +0100
        Re: need we support unshadowed passwords from the installer Steve McIntyre <steve@einval.com> - 2023-01-15 14:30 +0100
    Re: need we support unshadowed passwords from the installer Peter Pentchev <roam@ringlet.net> - 2023-01-14 13:20 +0100
    Re: need we support unshadowed passwords from the installer Peter Pentchev <roam@ringlet.net> - 2023-01-14 13:20 +0100
    Re: need we support unshadowed passwords from the installer Sam Hartman <hartmans@debian.org> - 2023-01-15 01:00 +0100
    Re: need we support unshadowed passwords from the installer nick black <dankamongmen@gmail.com> - 2023-01-15 20:10 +0100

#106816 — need we support unshadowed passwords from the installer

Fromnick black <dankamongmen@gmail.com>
Date2023-01-14 03:20 +0100
Subjectneed we support unshadowed passwords from the installer
Message-ID<FNEjf-fov-3@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

it's 2023 and imho time to stop supporting unshadowed passwords
from the installer.

 https://salsa.debian.org/installer-team/user-setup/-/merge_requests/5

1) nis (and possibly conserver?) seem the primary drivers of an
    unshadowed passwd.=20

let me freely admit that, despite the advanced age of forty-two
(seventy-eight in UNIX years), that i know nothing about nis/yp
except that there was a big o'reilly book about it back when one
read the security book with the big safe on the front and the
scripting book with the big drill. i suspect it's basically a
halfway point between syncing /etc/passwd and /etc/hosts with
cron+rsh, and hiring someone on whom you can inflict ldap? so
please correct me wherever i'm woefully ignorant.

...but it appears that NIS can be made to work with shadowed
passwords (though without their benefits). this is from a
cursory reading of a FAQ last updated in 2003, so take it with a
grain of salt. the "linux network administrators [sic] guide"
seems to confirm this, and can also help you set up IPX or UUCP.

2) it seems that the unshadowing of passwords is only a
   "/sbin/shadowconfig off" away. somewhere down the long road, we
   appear to have lost shadowconfig.8, but this is what i gather
   from web searches.

   i'd almost suggest this might want to go into the "nis"
   package, avoiding "why do we even have that lever"
   situations, but i resolutely oppose feature creep for this MR.

3) if someone accidentally selects this during install, i can't
    think of any means by which they'd find out during the course of
    typical systems administration.

4) i don't have to answer this question in any other installer
    i've used in the past decade, i'm pretty certain.

5) arch appears to support NIS without any mention of shadowing?
    though admittedly that wiki page is "somewhat unfinished"[0]

6) fedora has recently discussed eliminating NIS support
    entirely. it's a done deal in RHEL.

i'm absolutely not suggesting we stop supporting NIS or other
programs which rely on unshadowed passwords. it's a big ol'
tent, and we have more than enough room for you to carry forth
the torch of Solaris 2. i just don't think this belongs in the
installer anymore.

--rigorously, nick

[0] https://wiki.archlinux.org/title/NIS

-- 
nick black -=- https://www.nick-black.com
to make an apple pie from scratch,
you need first invent a universe.

[toc] | [next] | [standalone]


#106817

FromMarc Haber <mh+debian-devel@zugschlus.de>
Date2023-01-14 10:00 +0100
Message-ID<FNKyl-jhx-3@gated-at.bofh.it>
In reply to#106816
On Fri, 13 Jan 2023 21:11:40 -0500, nick black
<dankamongmen@gmail.com> wrote:
>i'm absolutely not suggesting we stop supporting NIS or other
>programs which rely on unshadowed passwords. it's a big ol'
>tent, and we have more than enough room for you to carry forth
>the torch of Solaris 2. i just don't think this belongs in the
>installer anymore.

Amen. NIS-based systems usually have professional administrators who
are well able to change the configuration.

Greetings
Marc
-- 
-------------------------------------- !! No courtesy copies, please !! -----
Marc Haber         |   " Questions are the         | Mailadresse im Header
Mannheim, Germany  |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834

[toc] | [prev] | [next] | [standalone]


#106821

Fromnick black <dankamongmen@gmail.com>
Date2023-01-14 15:20 +0100
Message-ID<FNPy1-mRn-1@gated-at.bofh.it>
In reply to#106817

[Multipart message — attachments visible in raw view] — view raw

Marc Haber left as an exercise for the reader:
> On Fri, 13 Jan 2023 21:11:40 -0500, nick black
> <dankamongmen@gmail.com> wrote:
> >i'm absolutely not suggesting we stop supporting NIS or other
> >programs which rely on unshadowed passwords. it's a big ol'
> >tent, and we have more than enough room for you to carry forth
> >the torch of Solaris 2. i just don't think this belongs in the
> >installer anymore.
> 
> Amen. NIS-based systems usually have professional administrators who
> are well able to change the configuration.

hahah, yes i thought you might support the idea based off
adduser changelogs circa 2005 =].

thanks to you and peter for voicing your support. i will head
off to #debian-boot and try to drum up a merge.

-- 
nick black -=- https://www.nick-black.com
to make an apple pie from scratch,
you need first invent a universe.

[toc] | [prev] | [next] | [standalone]


#106826

FromSteve McIntyre <steve@einval.com>
Date2023-01-15 14:30 +0100
Message-ID<FObfc-AJj-5@gated-at.bofh.it>
In reply to#106821
On Sat, Jan 14, 2023 at 09:18:59AM -0500, nick black wrote:
>Marc Haber left as an exercise for the reader:
>> On Fri, 13 Jan 2023 21:11:40 -0500, nick black
>> <dankamongmen@gmail.com> wrote:
>> >i'm absolutely not suggesting we stop supporting NIS or other
>> >programs which rely on unshadowed passwords. it's a big ol'
>> >tent, and we have more than enough room for you to carry forth
>> >the torch of Solaris 2. i just don't think this belongs in the
>> >installer anymore.
>> 
>> Amen. NIS-based systems usually have professional administrators who
>> are well able to change the configuration.
>
>hahah, yes i thought you might support the idea based off
>adduser changelogs circa 2005 =].
>
>thanks to you and peter for voicing your support. i will head
>off to #debian-boot and try to drum up a merge.

I'll be honest, I've been horrified for years that we can still ask
the shadow question. I hadn't realised it might be relevant for
NIS. Even so, +1 from me. Let's get this done, I think...

-- 
Steve McIntyre, Cambridge, UK.                                steve@einval.com
Is there anybody out there?

[toc] | [prev] | [next] | [standalone]


#106819

FromPeter Pentchev <roam@ringlet.net>
Date2023-01-14 13:20 +0100
Message-ID<FNNFT-lq4-5@gated-at.bofh.it>
In reply to#106816

[Multipart message — attachments visible in raw view] — view raw

On Sat, Jan 14, 2023 at 02:11:00PM +0200, Peter Pentchev wrote:
> On Fri, Jan 13, 2023 at 09:11:40PM -0500, nick black wrote:
> > it's 2023 and imho time to stop supporting unshadowed passwords
> > from the installer.
> > 
> >  https://salsa.debian.org/installer-team/user-setup/-/merge_requests/5
> > 
> > 1) nis (and possibly conserver?) seem the primary drivers of an
> >     unshadowed passwd.=20
> > 
> > let me freely admit that, despite the advanced age of forty-two
> > (seventy-eight in UNIX years), that i know nothing about nis/yp
> > except that there was a big o'reilly book about it back when one
> > read the security book with the big safe on the front and the
> > scripting book with the big drill. i suspect it's basically a
> > halfway point between syncing /etc/passwd and /etc/hosts with
> > cron+rsh, and hiring someone on whom you can inflict ldap? so
> > please correct me wherever i'm woefully ignorant.
> > 
> > ...but it appears that NIS can be made to work with shadowed
> > passwords (though without their benefits). this is from a
> > cursory reading of a FAQ last updated in 2003, so take it with a
> > grain of salt. the "linux network administrators [sic] guide"
> > seems to confirm this, and can also help you set up IPX or UUCP.
> [snip]
> > i'm absolutely not suggesting we stop supporting NIS or other
> > programs which rely on unshadowed passwords. it's a big ol'
> > tent, and we have more than enough room for you to carry forth
> > the torch of Solaris 2. i just don't think this belongs in the
> > installer anymore.
> 
> I know what NIS/YP is, I know of a couple of places where it is
> still in use, and, as Mark Haber said, the people running those

Um. Many apologies. Of course it's Marc.

> places know how to find and flip a switch.

-- 
Peter Pentchev  roam@ringlet.net roam@debian.org pp@storpool.com
PGP key:        http://people.FreeBSD.org/~roam/roam.key.asc
Key fingerprint 2EE7 A7A5 17FC 124C F115  C354 651E EFB0 2527 DF13

[toc] | [prev] | [next] | [standalone]


#106820

FromPeter Pentchev <roam@ringlet.net>
Date2023-01-14 13:20 +0100
Message-ID<FNNFT-lq4-7@gated-at.bofh.it>
In reply to#106816

[Multipart message — attachments visible in raw view] — view raw

On Fri, Jan 13, 2023 at 09:11:40PM -0500, nick black wrote:
> it's 2023 and imho time to stop supporting unshadowed passwords
> from the installer.
> 
>  https://salsa.debian.org/installer-team/user-setup/-/merge_requests/5
> 
> 1) nis (and possibly conserver?) seem the primary drivers of an
>     unshadowed passwd.=20
> 
> let me freely admit that, despite the advanced age of forty-two
> (seventy-eight in UNIX years), that i know nothing about nis/yp
> except that there was a big o'reilly book about it back when one
> read the security book with the big safe on the front and the
> scripting book with the big drill. i suspect it's basically a
> halfway point between syncing /etc/passwd and /etc/hosts with
> cron+rsh, and hiring someone on whom you can inflict ldap? so
> please correct me wherever i'm woefully ignorant.
> 
> ...but it appears that NIS can be made to work with shadowed
> passwords (though without their benefits). this is from a
> cursory reading of a FAQ last updated in 2003, so take it with a
> grain of salt. the "linux network administrators [sic] guide"
> seems to confirm this, and can also help you set up IPX or UUCP.
[snip]
> i'm absolutely not suggesting we stop supporting NIS or other
> programs which rely on unshadowed passwords. it's a big ol'
> tent, and we have more than enough room for you to carry forth
> the torch of Solaris 2. i just don't think this belongs in the
> installer anymore.

I know what NIS/YP is, I know of a couple of places where it is
still in use, and, as Mark Haber said, the people running those
places know how to find and flip a switch.

G'luck,
Peter

-- 
Peter Pentchev  roam@ringlet.net roam@debian.org pp@storpool.com
PGP key:        http://people.FreeBSD.org/~roam/roam.key.asc
Key fingerprint 2EE7 A7A5 17FC 124C F115  C354 651E EFB0 2527 DF13

[toc] | [prev] | [next] | [standalone]


#106823

FromSam Hartman <hartmans@debian.org>
Date2023-01-15 01:00 +0100
Message-ID<FNYBj-shO-3@gated-at.bofh.it>
In reply to#106816

[Multipart message — attachments visible in raw view] — view raw

>>>>> "nick" == nick black <dankamongmen@gmail.com> writes:

    nick> it's 2023 and imho time to stop supporting unshadowed
    nick> passwords from the installer.

Yes, absolutely.
I am familiar with nis/PAM/shadow/LDAP, have deployed NIS (although not
nisplus), and have been around long enough to understand the issues.

It is absolutely reasonable to expect people who need to do so to
unshadow their own passwords.

[toc] | [prev] | [next] | [standalone]


#106828

Fromnick black <dankamongmen@gmail.com>
Date2023-01-15 20:10 +0100
Message-ID<FOgye-E8e-7@gated-at.bofh.it>
In reply to#106816

[Multipart message — attachments visible in raw view] — view raw

Sam Hartman left as an exercise for the reader:
> Yes, absolutely.
> I am familiar with nis/PAM/shadow/LDAP, have deployed NIS (although not
> nisplus), and have been around long enough to understand the issues.
> 
> It is absolutely reasonable to expect people who need to do so to
> unshadow their own passwords.

thanks Steve McIntyre for the merge!

as an aside, as a fairly new DD, i've seen a lot of worry in
recent years about the difficulty of getting changes through
given the distributed ownership of packages, etc. i was frankly
worried about this being difficult to see through, despite it
being a small and agreed-upon change (there was certainly no way
i was going to NMU the installer).

it was merged this morning after authoring the MR through salsa
two evenings ago, quite painlessly. this is anecdotal and
perhaps not representative of Project dynamics as a whole, but i
for one feel more comfortable about proposing and executing
small changes like this now.

-- 
nick black -=- https://www.nick-black.com
to make an apple pie from scratch,
you need first invent a universe.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.devel


csiph-web