Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 10 Apr 1999 14:53:50 +0200
From:      Rico Pajarola <pajarola@cybertime.ch>
To:        security@FreeBSD.ORG
Cc:        Lauro Barbosa <lauro@pro.via-rs.com.br>
Subject:   Re: FreeBSD 2.2.8 and DES (again)
Message-ID:  <3.0.32.19990410144655.00b84ba0@shrike.overmind.ch>

next in thread | raw e-mail | index | archive | help
Tested that on several machines (DES as well as non-DES), 2.2.6, 3.1 and
current, and none of them shows this behaviour
Only when when the normal username is exactly 8 characters long (or 16 on
3.x and current), it ignores *any* excess characters...
eg on current, I have a user called testtesttesttest (16 characters), and I
can login as 'testtesttesttest' or as user 'testtesttesttest.' or as user
'testtesttesttestXXXXXXXXXX'.
At least OpenBSD 2.3 and AIX4 do this, too. RH Linux 5.2 and SunOS 5.6
don't (or they have much larger username limits, I don't know).

Rico

>Hello Again!
>        Please, I need help.
>        I have a server with FreeBSD 2.2.8 and DES instaled.
>        In this server the users can to login using login_name or
>login_name.
>(whit dot at end). for example: john or john.
>        Anybody know this problem ?
>        How can to correct this ?
>        Sorry my poor english.
>        Thanks,
>                Lauro.


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3.0.32.19990410144655.00b84ba0>