[net.sources.d] password expiration

geoff@desint.UUCP (05/22/86)

In article <548@rdin.UUCP> perl@rdin.UUCP (Robert Perlberg) writes:

> I don't know if this is what you're looking for, but UNIX has builtin
> password expiration.  It's documented in PASSWD(5).

I think this is limited to System V;  he was asking about BSD/Ultrix.
Also, the SV password-expiration scheme is a major security problem.  The
reasons for this are explained in detail in the Oct '84 issue of BSTJ,
in an article entitled "UNIX Operating System Security".  Briefly,
the problem is that the user is *forced* to choose a password at an
inconvenient time, so that passwords are chosen on the spur of the moment
and without adequate thought.

Followups to this posting will go to net.sources.d only.
-- 

	Geoff Kuenning
	{hplabs,ihnp4}!trwrb!desint!geoff