Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #264400 > unrolled thread
| Started by | gene heskett <gheskett@shentel.net> |
|---|---|
| First post | 2023-12-08 02:10 +0100 |
| Last post | 2023-12-08 22:50 +0100 |
| Articles | 13 — 10 participants |
Back to article view | Back to linux.debian.user
debian forgot usr pw gene heskett <gheskett@shentel.net> - 2023-12-08 02:10 +0100
Re: debian forgot usr pw Greg Wooledge <greg@wooledge.org> - 2023-12-08 02:30 +0100
Re: debian forgot usr pw gene heskett <gheskett@shentel.net> - 2023-12-08 02:50 +0100
Re: debian forgot usr pw John Hasler <john@sugarbit.com> - 2023-12-08 06:10 +0100
Re: debian forgot usr pw Pocket <pocket@columbus.rr.com> - 2023-12-08 14:00 +0100
Re: debian forgot usr pw Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2023-12-09 07:40 +0100
Re: debian forgot usr pw Pocket <pocket@columbus.rr.com> - 2023-12-09 15:10 +0100
Re: debian forgot usr pw Max Nikulin <manikulin@gmail.com> - 2023-12-08 06:20 +0100
Re: debian forgot usr pw yxcv@vienna.at - 2023-12-08 09:20 +0100
Re: debian forgot usr pw debian-user@howorth.org.uk - 2023-12-08 12:30 +0100
Re: debian forgot usr pw Anders Andersson <pipatron@gmail.com> - 2023-12-08 20:10 +0100
Re: debian forgot usr pw John Hasler <john@sugarbit.com> - 2023-12-08 06:10 +0100
Re: debian forgot usr pw David Christensen <dpchrist@holgerdanske.com> - 2023-12-08 22:50 +0100
| From | gene heskett <gheskett@shentel.net> |
|---|---|
| Date | 2023-12-08 02:10 +0100 |
| Subject | debian forgot usr pw |
| Message-ID | <HIxxn-c3Qq-1@gated-at.bofh.it> |
I had a 3d slicer I was quitting to restart it and re-organish its caxhe, took my machine to a lockup showing half a workspace on one half the screen and half an adjacent workspace on the other half of the screen, no responce to the keyboard and no mouse. 28 days uptime which was better than most uptimes I have with bookworm. 2 weeks seems to be the norm. TL;DR: So I went to the front panel and pressed the reset button but when it came time to enter my pw, it just looped back to the login prompt. So I did a full powerdown, enough times the psu finally went face down in the pool. That was a good excuse to do an overdue D & C and some update installs while I was changing the supply, adding a 16 port sata-III controller and 8T worth of SSD's so I could use them to get amanda started again. Powered it up, bios found the new drives, but my pw was still rejected, it looped back to the login in 2 or 3 seconds. I do not normally have a root pw set, just me, using sudo when I need to do root stuff. So at grub I hit e and changed quiet to single, eventually spotting in all the spew, something go flying by about the root account being locked, so "single" does not work. And of course no scrollback to read that msgs detail. Thats bug #1. Single for rescue demands a root pw. If no root, it should default to the name in the sudoers file. So I'm still locked out and this is the 3rd time debian 12 has done this to me. So I get out a 12.2 net-install dvd and reboot to it, several times, but I was able to set a root pw so single worked but I still had to enter the new pw. At this point I successfully changed /my/ passwd to something a bit longer expressing my frustration. So since all my other machine control machines have a full desktop with full net access, I went to one of the bananapi-m5's and sent firefox to google with the search string "linux login loops back to login", 2nd hit, on stackexchange said to delete anything that looked like ./XAuthority* and ditto ./xsession* something was contaminated, killing x or its newer wayland cousin. Bingo! Next reboot was normal. So that is bug #3. Deleting that stuff, possibly losing some setup details by then re-starting X (etc) with a clean slate is far more preferable to another format and reinstall just to delete the contaminated files, formatting everything and losing 25 years of my history like happened when those 2 new 2T seacrates died at about 6 weeks runtime, within hours of each other a bit over a year ago. Seems to me stuff like this ought to be fixable. Many thanks for reading this far. Maybe someone with write perms on bugzilla can investigate? Cheers, Gene Heskett. -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author, 1940) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis
[toc] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2023-12-08 02:30 +0100 |
| Message-ID | <HIxQJ-c3Wg-1@gated-at.bofh.it> |
| In reply to | #264400 |
On Thu, Dec 07, 2023 at 08:06:52PM -0500, gene heskett wrote: > Thats bug #1. Single for rescue demands a root pw. This isn't a bug. It's just how things *are*. People who choose not to set a root password are simply setting themselves up for this failure. It *will* happen eventually. I strongly recommend setting a root password on your systems. And you should either *use* it once in a while, so you don't forget what it is, or else make it the same as your regular account's password. So you don't forget what it is. If you *still* choose not to set a root password, then you will need to know how to get around the issue you ran into. You won't be able to use single-user mode to rescue your system, so you'll need other ways. There are two straightforward alternatives: boot from external media (USB or CD or DVD), or learn how to do the "init=/bin/bash" thing from your boot loader, which includes bind-mounting /proc and /dev and so on.
[toc] | [prev] | [next] | [standalone]
| From | gene heskett <gheskett@shentel.net> |
|---|---|
| Date | 2023-12-08 02:50 +0100 |
| Message-ID | <HIya5-c42b-5@gated-at.bofh.it> |
| In reply to | #264401 |
On 12/7/23 20:24, Greg Wooledge wrote: > On Thu, Dec 07, 2023 at 08:06:52PM -0500, gene heskett wrote: >> Thats bug #1. Single for rescue demands a root pw. > > This isn't a bug. It's just how things *are*. > > People who choose not to set a root password are simply setting themselves > up for this failure. It *will* happen eventually. I strongly recommend > setting a root password on your systems. And you should either *use* it > once in a while, so you don't forget what it is, or else make it the same > as your regular account's password. So you don't forget what it is. > > If you *still* choose not to set a root password, then you will need to > know how to get around the issue you ran into. You won't be able to use > single-user mode to rescue your system, so you'll need other ways. There > are two straightforward alternatives: boot from external media (USB or CD > or DVD), or learn how to do the "init=/bin/bash" thing from your boot > loader, which includes bind-mounting /proc and /dev and so on. > > . I've now set a root pw, about 34 chars, so they'll be a couple eons guessing it AND (horrors) have written it down. Cheers, Gene Heskett. -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author, 1940) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2023-12-08 06:10 +0100 |
| Message-ID | <HIBhD-c675-1@gated-at.bofh.it> |
| In reply to | #264402 |
Gene writes: > AND (horrors) have written it down. That's the right thing to do. -- John Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Pocket <pocket@columbus.rr.com> |
|---|---|
| Date | 2023-12-08 14:00 +0100 |
| Message-ID | <HIICt-caqJ-1@gated-at.bofh.it> |
| In reply to | #264411 |
On 12/8/23 00:05, John Hasler wrote: > Gene writes: >> AND (horrors) have written it down. > That's the right thing to do. Well you could always use the universal password of password I use for example i use the following for the root account the password is root for my user account of pocket the password is pocket No one will every guess those password so I am completely protected -- It's not easy to be me
[toc] | [prev] | [next] | [standalone]
| From | Timothy M Butterworth <timothy.m.butterworth@gmail.com> |
|---|---|
| Date | 2023-12-09 07:40 +0100 |
| Message-ID | <HIZah-ckrP-1@gated-at.bofh.it> |
| In reply to | #264417 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Dec 8, 2023 at 7:56 AM Pocket <pocket@columbus.rr.com> wrote: > > On 12/8/23 00:05, John Hasler wrote: > > Gene writes: > >> AND (horrors) have written it down. > > That's the right thing to do. > > Well you could always use the universal password of password > > I use for example i use the following > > for the root account the password is root > > for my user account of pocket the password is pocket > > No one will every guess those password so I am completely protected > Thanks now I have your passwords and your IP address from the SMTP header. 2001:41b8:202:deb:216:36ff:fe40:4002 Darn SSH is configured to use certificates. Your security is stronger than you let on. -- > > It's not easy to be me > > -- ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/ ⠈⠳⣄⠀⠀
[toc] | [prev] | [next] | [standalone]
| From | Pocket <pocket@columbus.rr.com> |
|---|---|
| Date | 2023-12-09 15:10 +0100 |
| Message-ID | <HJ6bL-coO8-5@gated-at.bofh.it> |
| In reply to | #264465 |
[Multipart message — attachments visible in raw view] — view raw
On 12/9/23 01:29, Timothy M Butterworth wrote: > > > On Fri, Dec 8, 2023 at 7:56 AM Pocket <pocket@columbus.rr.com> wrote: > > > On 12/8/23 00:05, John Hasler wrote: > > Gene writes: > >> AND (horrors) have written it down. > > That's the right thing to do. > > Well you could always use the universal password of password > > I use for example i use the following > > for the root account the password is root > > for my user account of pocket the password is pocket > > No one will every guess those password so I am completely protected > > > Thanks now I have your passwords and your IP address from the SMTP > header. 2001:41b8:202:deb:216:36ff:fe40:4002 Darn SSH is configured to > use certificates. Your security is stronger than you let on. LOL whois 2001:41b8:202:deb:216:36ff:fe40:4002 % This is the RIPE Database query service. % The objects are in RPSL format. % % The RIPE Database is subject to Terms and Conditions. % See https://apps.db.ripe.net/docs/HTML-Terms-And-Conditions % Note: this output has been filtered. % To receive output for a database update, use the "-B" flag. % Information related to '2001:41b8:202::/48' % Abuse contact for '2001:41b8:202::/48' is 'abuse@man-da.de' inet6num: 2001:41b8:202::/48 netname: DE-MANDA-DEBIAN-V6-01 descr: Debian Darmstadt Network country: DE admin-c: DSAT1-RIPE tech-c: MAND2-RIPE status: ASSIGNED mnt-by: MANDA-MNT created: 2015-07-09T09:24:37Z last-modified: 2015-07-09T09:24:37Z source: RIPE # Filtered role: Debian System Administrators Team address: Software in the Public Interest, Inc address: Debian Project address: 1732 1st Ave #20327 address: New York, NY 10128-5177 address: United States org: ORG-DA330-RIPE remarks: ******************************************** remarks: ** in case of emergency find us on IRC ** remarks: ** irc://irc.debian.org/#debian-admin ** remarks: ******************************************** remarks: ** remarks: ******************************************** remarks: ** Direct peering requests to ** remarks: ** peering@debian.org ** remarks: ******************************************** That doesn't belong to me > > -- > > It's not easy to be me > > > > -- > ⢀⣴⠾⠻⢶⣦⠀ > ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system > ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/ > ⠈⠳⣄⠀⠀ -- It's not easy to be me
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2023-12-08 06:20 +0100 |
| Message-ID | <HIBrj-c6aH-1@gated-at.bofh.it> |
| In reply to | #264402 |
On 08/12/2023 08:49, gene heskett wrote: > I've now set a root pw, about 34 chars, so they'll be a couple eons > guessing it AND (horrors) have written it down. Consider pass phrases. <https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases> Deep Dive: EFF's New Wordlists for Random Passphrases By Joseph Bonneau July 19, 2016 is declared to be an improvement of diceware. kepassxc supports generation of pass phrases based on the EFF word list. A couple of memorable pass phrases (for different scopes) may protect other passwords stored in a password manager. https://xkcd.com/936/ Password Strength > To anyone who understands information theory and security and is in an > infuriating argument with someone who does not (possibly involving mixed > case), I sincerely apologize.
[toc] | [prev] | [next] | [standalone]
| From | yxcv@vienna.at |
|---|---|
| Date | 2023-12-08 09:20 +0100 |
| Message-ID | <HIEfv-c7Un-1@gated-at.bofh.it> |
| In reply to | #264412 |
On Fri, 8 Dec 2023 12:17:35 +0700 Max Nikulin <manikulin@gmail.com> wrote: > > On 08/12/2023 08:49, gene heskett wrote: >> I've now set a root pw, about 34 chars, so they'll be a couple eons >>guessing it AND (horrors) have written it down. > > Consider pass phrases. > > <https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases> > Deep Dive: EFF's New Wordlists for Random Passphrases > By Joseph Bonneau July 19, 2016 > > is declared to be an improvement of diceware. What is diceware? Why trust EFF? > kepassxc supports generation of pass phrases based on the EFF word >list. A couple of memorable pass phrases (for different scopes) may >protect other passwords stored in a password manager. > > https://xkcd.com/936/ Password Strength Or trusting "https://xkcd.com/936/ Password Strength" ?
[toc] | [prev] | [next] | [standalone]
| From | debian-user@howorth.org.uk |
|---|---|
| Date | 2023-12-08 12:30 +0100 |
| Message-ID | <HIHdn-c9JZ-19@gated-at.bofh.it> |
| In reply to | #264413 |
yxcv@vienna.at wrote: > On Fri, 8 Dec 2023 12:17:35 +0700 > Max Nikulin <manikulin@gmail.com> wrote: > > > > On 08/12/2023 08:49, gene heskett wrote: > >> I've now set a root pw, about 34 chars, so they'll be a couple > >> eons > >>guessing it AND (horrors) have written it down. > > > > Consider pass phrases. > > > > <https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases> > > Deep Dive: EFF's New Wordlists for Random Passphrases > > By Joseph Bonneau July 19, 2016 > > > > is declared to be an improvement of diceware. > > What is diceware? Try asking google > Why trust EFF? See above > > kepassxc supports generation of pass phrases based on the EFF word > >list. A couple of memorable pass phrases (for different scopes) may > >protect other passwords stored in a password manager. > > > > https://xkcd.com/936/ Password Strength > > Or trusting "https://xkcd.com/936/ Password Strength" ? Nobody's asking you to?
[toc] | [prev] | [next] | [standalone]
| From | Anders Andersson <pipatron@gmail.com> |
|---|---|
| Date | 2023-12-08 20:10 +0100 |
| Message-ID | <HIOoy-ce4X-15@gated-at.bofh.it> |
| In reply to | #264413 |
On Fri, Dec 8, 2023 at 9:10 AM <yxcv@vienna.at> wrote: > > On Fri, 8 Dec 2023 12:17:35 +0700 > Max Nikulin <manikulin@gmail.com> wrote: > > > > On 08/12/2023 08:49, gene heskett wrote: > >> I've now set a root pw, about 34 chars, so they'll be a couple eons > >>guessing it AND (horrors) have written it down. > > > > Consider pass phrases. > > > > <https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases> > > Deep Dive: EFF's New Wordlists for Random Passphrases > > By Joseph Bonneau July 19, 2016 > > > > is declared to be an improvement of diceware. > > What is diceware? > Why trust EFF? > > > kepassxc supports generation of pass phrases based on the EFF word > >list. A couple of memorable pass phrases (for different scopes) may > >protect other passwords stored in a password manager. > > > > https://xkcd.com/936/ Password Strength > > Or trusting "https://xkcd.com/936/ Password Strength" ? The xkcd link has all the information necessary to explain why it can be trusted. It's like asking "Why trust that 1+1=2?" Maybe it's not, but that's a philosophical question for snotty teenagers, not a question for anyone doing anything useful.
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2023-12-08 06:10 +0100 |
| Message-ID | <HIBhD-c675-3@gated-at.bofh.it> |
| In reply to | #264401 |
Greg writes: > And you should either *use* it once in a while, so you don't forget > what it is, or else make it the same as your regular account's > password. Write the damn thing down. The world won't end. -- John "Write all your passwords down. It isn't 1980 anymore." Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | David Christensen <dpchrist@holgerdanske.com> |
|---|---|
| Date | 2023-12-08 22:50 +0100 |
| Message-ID | <HIQTn-cfqe-11@gated-at.bofh.it> |
| In reply to | #264400 |
On 12/7/23 17:06, gene heskett wrote: > I had a 3d slicer I was quitting to restart it and re-organish its > caxhe, took my machine to a lockup showing half a workspace on one half > the screen and half an adjacent workspace on the other half of the > screen, no responce to the keyboard and no mouse. 28 days uptime which > was better than most uptimes I have with bookworm. 2 weeks seems to be > the norm. > > TL;DR: > > So I went to the front panel and pressed the reset button but when it > came time to enter my pw, it just looped back to the login prompt. So I > did a full powerdown, enough times the psu finally went face down in the > pool. That was a good excuse to do an overdue D & C and some update > installs while I was changing the supply, adding a 16 port sata-III > controller and 8T worth of SSD's so I could use them to get amanda > started again. Powered it up, bios found the new drives, but my pw was > still rejected, it looped back to the login in 2 or 3 seconds. A failing power supply can cause very strange behavior, including file corruption that will haunt you after replacing the power supply. > I do not normally have a root pw set, just me, using sudo when I need to > do root stuff. So at grub I hit e and changed quiet to single, > eventually spotting in all the spew, something go flying by about the > root account being locked, so "single" does not work. And of course no > scrollback to read that msgs detail. > > Thats bug #1. Single for rescue demands a root pw. If no root, it should > default to the name in the sudoers file. So I'm still locked out and > this is the 3rd time debian 12 has done this to me. So I get out a 12.2 > net-install dvd and reboot to it, several times, but I was able to set a > root pw so single worked but I still had to enter the new pw. While I always set a root password, I do agree that people should be able to run Debian without a root password and everything should still work. Perhaps you should consider filing a bug report against grub (?). > At this point I successfully changed /my/ passwd to something a bit > longer expressing my frustration. So since all my other machine control > machines have a full desktop with full net access, I went to one of the > bananapi-m5's and sent firefox to google with the search string "linux > login loops back to login", 2nd hit, on stackexchange said to delete > anything that looked like ./XAuthority* and ditto ./xsession* something > was contaminated, killing x or its newer wayland cousin. Bingo! Next > reboot was normal. > > So that is bug #3. Deleting that stuff, possibly losing some setup > details by then re-starting X (etc) with a clean slate is far more > preferable to another format and reinstall just to delete the > contaminated files, formatting everything and losing 25 years of my > history like happened when those 2 new 2T seacrates died at about 6 > weeks runtime, within hours of each other a bit over a year ago. > > Seems to me stuff like this ought to be fixable. > > Many thanks for reading this far. Maybe someone with write perms on > bugzilla can investigate? > > Cheers, Gene Heskett. If I am understanding you correctly, $HOME/.Xauthority and/or $HOME/.xsession-errors became corrupt when the PSU failed, and the fix was to replace the PSU and delete those files? About the only idea that comes to mind would be to put in a feature request against Xorg that Xorg implement some automatic failure recovery protocol that includes those files when Xorg fails to start the windowing environment. That said, I have little faith in the "find the needle in the haystack" and "put Humpty Dumpty back together again" approach to fixing operating system instances. Even when it "seems to work", I rarely have confidence in the results -- "what needles did I miss?" My response to this situation is disaster preparedness -- I take images of my OS drives monthly, or as needed. In fact, I had a UEFI Debian image go sideways last weekend during maintenance. I spent ~15 minutes investigating/ trouble-shooting/ STFW/ RTFM/ etc., could not find the answer, spent ~15 minutes re-imaging, spent ~15 minutes updating, and was back in business with a known good OS instance in less than an hour without any outside help. David
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web