debian/NEWS: Fix false claim about PREVENT_NO_AUTH affecting authentication

Also drop setting PREVENT_NO_AUTH in shipped login.defs.

Closes: #1041547
This commit is contained in:
Balint Reczey
2023-09-25 17:15:46 +02:00
parent 05a41bc4d5
commit 4806645316
2 changed files with 8 additions and 8 deletions
Vendored
+8
View File
@@ -1,3 +1,11 @@
shadow (1:4.13+dfsg1-2) unstable; urgency=medium
The previous entry falsely states that PREVENT_NO_AUTH in /etc/login.defs
affects authentication. The historical default of letting all users with
empty password field in without authentication is still in effect.
-- Balint Reczey <balint@balintreczey.hu> Mon, 25 Sep 2023 17:04:09 +0200
shadow (1:4.11.1+dfsg1-0exp1) experimental; urgency=medium
Login now prevents an empty password field to be interpreted as
-8
View File
@@ -337,14 +337,6 @@ NONEXISTENT /nonexistent
#
#GRANT_AUX_GROUP_SUBIDS yes
#
# Prevents an empty password field to be interpreted as "no authentication
# required".
# Set to "yes" to prevent for all accounts
# Set to "superuser" to prevent for UID 0 / root (default)
# Set to "no" to not prevent for any account (dangerous, historical default)
PREVENT_NO_AUTH superuser
#
# Select the HMAC cryptography algorithm.
# Used in pam_timestamp module to calculate the keyed-hash message