Kerberos Password Policies

From Syscore

Here is the current default password policy on the KDC:

kadmin:  getpol default
Policy: default
Maximum password life: 0
Minimum password life: 0
Minimum password length: 6
Minimum number of password character classes: 1
Number of old keys kept: 1

In addition to the password "policy" set here, the 'kadmin' daemon on the KDC has been modified to check all user password changes through the Cracklib library, with a rather large dictionary of both English and foreign words -- necessary when you have a large quantity of foreign students & employees.