When performing this task one encounters one fundamental difficulty: The /etc/shadow file is supposed to be read/writeable only by root. However, the webserver is supposed to run under a non-root user, such as “nobody”. mod_auth_shadow addresses this difficulty by opening a pipe to an suid root program, validate, which does the actual validation. When there is a failure, validate writes an error message to the system log, and waits three seconds before exiting.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Fedora | 11 | any | mod_auth_shadow | < 2.2 | UNKNOWN |