[Date Prev][Date Next] [Chronological] [Thread] [Top]

(ITS#3777) ppolicy password quality check is broken



Full_Name: Howard Chu
Version: HEAD/2.3
OS: 
URL: ftp://ftp.openldap.org/incoming/
Submission from: (NULL) (24.126.120.178)
Submitted by: hyc


When pwdCheckQuality is set to 2 the module is supposed to reject passwordModify
requests if the new password is already hashed (and its quality cannot be
checked). Currently it silently accepts the password instead of rejecting it.