* Copyright (c) 1990, 1993, 1994
* The Regents of the University of California. All rights reserved.
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
* 3. All advertising materials mentioning features or use of this software
* must display the following acknowledgement:
* This product includes software developed by the University of
* California, Berkeley and its contributors.
* 4. Neither the name of the University nor the names of its contributors
* may be used to endorse or promote products derived from this software
* without specific prior written permission.
* THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
* ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
static char sccsid
[] = "@(#)local_passwd.c 8.3 (Berkeley) 4/2/94";
static unsigned char itoa64
[] = /* 0 ... 63 => ascii - 64 */
"./0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
char buf
[_PASSWORD_LEN
+1], salt
[9];
(void)printf("Changing local password for %s.\n", pw
->pw_name
);
if (uid
&& pw
->pw_passwd
[0] &&
strcmp(crypt(getpass("Old password:"), pw
->pw_passwd
),
for (buf
[0] = '\0', tries
= 0;;) {
p
= getpass("New password:");
(void)printf("Password unchanged.\n");
if (strlen(p
) <= 5 && (uid
!= 0 || ++tries
< 2)) {
(void)printf("Please enter a longer password.\n");
for (t
= p
; *t
&& islower(*t
); ++t
);
if (!*t
&& (uid
!= 0 || ++tries
< 2)) {
(void)printf("Please don't use an all-lower case password.\nUnusual capitalization, control characters or digits are suggested.\n");
if (!strcmp(buf
, getpass("Retype new password:")))
(void)printf("Mismatch; try again, EOF to quit.\n");
/* grab a random printable character that isn't a colon */
(void)srandom((int)time((time_t *)NULL
));
salt
[0] = _PASSWORD_EFMT1
;
to64(&salt
[1], (long)(29 * 25), 4);
to64(&salt
[5], random(), 4);
to64(&salt
[0], random(), 2);
return (crypt(buf
, salt
));
if (!(pw
= getpwnam(uname
)))
errx(1, "unknown user %s", uname
);
if (uid
&& uid
!= pw
->pw_uid
)
errx(1, "%s", strerror(EACCES
));
* Get the new password. Reset passwd change time to zero; when
* classes are implemented, go and get the "offset" value for this
* class and reset the timer.
pw
->pw_passwd
= getnewpasswd(pw
);
pw_error((char *)NULL
, 0, 1);