xref: /netbsd-src/share/man/man5/passwd.conf.5 (revision 0e837f732b8b03979bb65f4748748593eeead882)
1.\"	$NetBSD: passwd.conf.5,v 1.13 2021/10/26 20:44:45 nia Exp $
2.\"
3.\" Copyright 1997 Niels Provos <provos@physnet.uni-hamburg.de>
4.\" All rights reserved.
5.\"
6.\" Redistribution and use in source and binary forms, with or without
7.\" modification, are permitted provided that the following conditions
8.\" are met:
9.\" 1. Redistributions of source code must retain the above copyright
10.\"    notice, this list of conditions and the following disclaimer.
11.\" 2. Redistributions in binary form must reproduce the above copyright
12.\"    notice, this list of conditions and the following disclaimer in the
13.\"    documentation and/or other materials provided with the distribution.
14.\" 3. All advertising materials mentioning features or use of this software
15.\"    must display the following acknowledgement:
16.\"      This product includes software developed by Niels Provos.
17.\" 4. The name of the author may not be used to endorse or promote products
18.\"    derived from this software without specific prior written permission.
19.\"
20.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
21.\" IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
22.\" OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
23.\" IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
24.\" INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
25.\" NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
26.\" DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
27.\" THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
28.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
29.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
30.\"
31.Dd October 26, 2021
32.Dt PASSWD.CONF 5
33.Os
34.Sh NAME
35.Nm passwd.conf
36.Nd password encryption configuration file
37.Sh SYNOPSIS
38.Nm
39.Sh DESCRIPTION
40The
41.Pa /etc/passwd.conf
42file, consisting of
43.Dq stanzas ,
44describes the configuration of the password cipher used
45to encrypt local or YP passwords.
46.Pp
47There are default, user and group specific stanzas.
48If no user or group
49stanza to a specific option is available, the default stanza
50is used.
51.Pp
52To differentiate between user and group stanzas, groups are prefixed
53with a single colon
54.Pq Sq \&: .
55.Pp
56Some fields and their possible values that can appear in this file are:
57.Bl -tag -width localcipher
58.It Sy localcipher
59The cipher to use for local passwords.
60.Pp
61Possible values are:
62.Dq argon2d,<t=X,m=Y,p=Z> ,
63.Dq argon2i,<t=X,m=Y,p=Z> ,
64.Dq argon2id,<t=X,m=Y,p=Z> ,
65.Dq old ,
66.Dq newsalt,<rounds> ,
67.Dq md5 ,
68.Dq sha1,<rounds> ,
69and
70.Dq blowfish,<rounds> .
71.Pp
72For
73.Dq argon2d ,
74.Dq argon2i ,
75and
76.Dq argon2id ,
77optional hardness parameters can be specified as described in the
78manual for
79.Xr pwhash 1 .
80.Pp
81For
82.Dq newsalt
83the value of rounds is a 24-bit integer with a minimum of 7250 rounds.
84.Pp
85For
86.Dq sha1
87the value of rounds is a 32-bit integer, 0 means use the default
88of 24680.
89.Pp
90For
91.Dq blowfish
92the value can be between 4 and 31.
93It specifies the base 2 logarithm of the number of rounds.
94.Pp
95If not specified, the default value is
96.Dq old .
97.It Sy ypcipher
98The cipher to use for YP passwords.
99.Pp
100The possible values are the same as for localcipher.
101.Pp
102If not specified, the default value is
103.Dq old .
104.El
105.Pp
106To retrieve information from this file use
107.Xr pw_getconf 3 .
108.Sh FILES
109.Bl -tag -width /etc/passwd.conf -compact
110.It Pa /etc/passwd.conf
111.El
112.Sh EXAMPLES
113Use SHA1 as the local cipher and old-style DES as the YP cipher.
114Use blowfish with 2^5 rounds for root:
115.Bd -literal
116 default:
117      localcipher = sha1
118      ypcipher = old
119
120 root:
121      localcipher = blowfish,5
122.Ed
123.Sh SEE ALSO
124.Xr passwd 1 ,
125.Xr pwhash 1 ,
126.Xr pw_getconf 3 ,
127.Xr passwd 5
128.Sh HISTORY
129The
130.Nm
131configuration file first appeared in
132.Nx 1.6 .
133.Pp
134The default value of
135.Sy localcipher
136was set to
137.Dq sha1
138in
139.Pa /etc/passwd.conf
140starting from
141.Nx 6.0 .
142.Pp
143The default value of
144.Sy localcipher
145was set to
146.Dq argon2id
147in
148.Pa /etc/passwd.conf
149starting from
150.Nx 10.0 .
151