update-cracklib does not include newly installed wordlists

Bug #304307 reported by Shiv V
4
Affects Status Importance Assigned to Milestone
cracklib2 (Debian)
Fix Released
Unknown
cracklib2 (Ubuntu)
Fix Released
Undecided
Jan Dittberner

Bug Description

Binary package hint: cracklib-runtime

I installed libpam-cracklib then a bunch of wordlists. Running the cracklib-runtime daily cron script does not update the dictionary in /var/cache/cracklib. Turns out that the cron job calls /usr/sbin/update-cracklib, which compares the mod times of wordlist files to the dictionary in /var/cache/cracklib and does not include the wordlist unless it is newer than the dictionary. Makes sense except that the timestamps on the newly installed dictionaries do not reflect when they were installed but rather when they were packaged. Workaround is to delete the files in /var/cache/cracklib and rebuild from scratch using the cron job.

Ubuntu: 8.10 i386
cracklib-runtime: 2.8.12-2ubuntu1

Revision history for this message
Jan Dittberner (jan-dittberner) wrote :

Thanks for the report. I think we need better heuristics to decide whether to update the dictionary. I'll try to figure out a solution.

Changed in cracklib2:
assignee: nobody → jan-dittberner
status: New → Confirmed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package cracklib2 - 2.8.13-4

---------------
cracklib2 (2.8.13-4) unstable; urgency=low

  * debian/update-cracklib: add a check whether all installed
    dictionaries were used to create the existing cracklib dictionary
    (Closes: #508255 and LP: #304307)
  * add descriptions to the quilt patches (fixes lintian warnings)

 -- Ubuntu Archive Auto-Sync <email address hidden> Mon, 15 Dec 2008 10:20:02 +0000

Changed in cracklib2:
status: Confirmed → Fix Released
Changed in cracklib2:
status: Unknown → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.