Password Expiration Limits and PAM Override Behavior
0 reputation · 31 Aug 2022, 06:24 UTC
Credential Lifecycle Management
Debian systems utilize /etc/login.defs to define system-wide defaults for PASS_MAX_DAYS and PASS_WARN_AGE, which govern the lifecycle of user credentials. These settings are intended to enforce periodic password rotation to maintain security standards.
PAM Integration Constraints
The Pluggable Authentication Modules (PAM) framework can introduce configurations that supersede the values defined in the shadow password suite. When a user's password expires, the interaction between the chage attributes and specific PAM modules determines whether the account is immediately locked or allows a grace period for updates.
There is uncertainty regarding the priority of enforcement when /etc/login.defs and PAM modules provide conflicting instructions for expired credential handling.
- Does the PAM configuration take absolute precedence over the
PASS_MAX_DAYSsetting during the authentication phase? - Under what specific conditions will a PAM module ignore the
PASS_WARN_AGEgrace period?