From 917979b52ceb2519be8b114ecb51d6a8e01fe0d7 Mon Sep 17 00:00:00 2001 From: Sumit Bose Date: Thu, 5 Mar 2009 15:50:40 +0100 Subject: added password reset by root --- server/responder/pam/pam_LOCAL_domain.c | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'server/responder') diff --git a/server/responder/pam/pam_LOCAL_domain.c b/server/responder/pam/pam_LOCAL_domain.c index 995dfc2d..4671eb9b 100644 --- a/server/responder/pam/pam_LOCAL_domain.c +++ b/server/responder/pam/pam_LOCAL_domain.c @@ -310,6 +310,11 @@ static void pam_handler_callback(void *pvt, int ldb_status, switch (lreq->pd->cmd) { case SSS_PAM_AUTHENTICATE: case SSS_PAM_CHAUTHTOK: + if (lreq->pd->cmd == SSS_PAM_CHAUTHTOK && lreq->cctx->priv == 1) { +/* TODO: maybe this is a candiate for an explicit audit message. */ + DEBUG(4, ("allowing root to reset a password.\n")); + break; + } ret = authtok2str(lreq, lreq->pd->authtok, lreq->pd->authtok_size, &authtok); NEQ_CHECK_OR_JUMP(ret, EOK, ("authtok2str failed.\n"), -- cgit