1.\" $NetBSD: passwd.conf.5,v 1.13 2021/10/26 20:44:45 nia Exp $ 2.\" 3.\" Copyright 1997 Niels Provos <provos@physnet.uni-hamburg.de> 4.\" All rights reserved. 5.\" 6.\" Redistribution and use in source and binary forms, with or without 7.\" modification, are permitted provided that the following conditions 8.\" are met: 9.\" 1. Redistributions of source code must retain the above copyright 10.\" notice, this list of conditions and the following disclaimer. 11.\" 2. Redistributions in binary form must reproduce the above copyright 12.\" notice, this list of conditions and the following disclaimer in the 13.\" documentation and/or other materials provided with the distribution. 14.\" 3. All advertising materials mentioning features or use of this software 15.\" must display the following acknowledgement: 16.\" This product includes software developed by Niels Provos. 17.\" 4. The name of the author may not be used to endorse or promote products 18.\" derived from this software without specific prior written permission. 19.\" 20.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 21.\" IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 22.\" OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 23.\" IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 24.\" INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 25.\" NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 26.\" DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 27.\" THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 28.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 29.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 30.\" 31.Dd October 26, 2021 32.Dt PASSWD.CONF 5 33.Os 34.Sh NAME 35.Nm passwd.conf 36.Nd password encryption configuration file 37.Sh SYNOPSIS 38.Nm 39.Sh DESCRIPTION 40The 41.Pa /etc/passwd.conf 42file, consisting of 43.Dq stanzas , 44describes the configuration of the password cipher used 45to encrypt local or YP passwords. 46.Pp 47There are default, user and group specific stanzas. 48If no user or group 49stanza to a specific option is available, the default stanza 50is used. 51.Pp 52To differentiate between user and group stanzas, groups are prefixed 53with a single colon 54.Pq Sq \&: . 55.Pp 56Some fields and their possible values that can appear in this file are: 57.Bl -tag -width localcipher 58.It Sy localcipher 59The cipher to use for local passwords. 60.Pp 61Possible values are: 62.Dq argon2d,<t=X,m=Y,p=Z> , 63.Dq argon2i,<t=X,m=Y,p=Z> , 64.Dq argon2id,<t=X,m=Y,p=Z> , 65.Dq old , 66.Dq newsalt,<rounds> , 67.Dq md5 , 68.Dq sha1,<rounds> , 69and 70.Dq blowfish,<rounds> . 71.Pp 72For 73.Dq argon2d , 74.Dq argon2i , 75and 76.Dq argon2id , 77optional hardness parameters can be specified as described in the 78manual for 79.Xr pwhash 1 . 80.Pp 81For 82.Dq newsalt 83the value of rounds is a 24-bit integer with a minimum of 7250 rounds. 84.Pp 85For 86.Dq sha1 87the value of rounds is a 32-bit integer, 0 means use the default 88of 24680. 89.Pp 90For 91.Dq blowfish 92the value can be between 4 and 31. 93It specifies the base 2 logarithm of the number of rounds. 94.Pp 95If not specified, the default value is 96.Dq old . 97.It Sy ypcipher 98The cipher to use for YP passwords. 99.Pp 100The possible values are the same as for localcipher. 101.Pp 102If not specified, the default value is 103.Dq old . 104.El 105.Pp 106To retrieve information from this file use 107.Xr pw_getconf 3 . 108.Sh FILES 109.Bl -tag -width /etc/passwd.conf -compact 110.It Pa /etc/passwd.conf 111.El 112.Sh EXAMPLES 113Use SHA1 as the local cipher and old-style DES as the YP cipher. 114Use blowfish with 2^5 rounds for root: 115.Bd -literal 116 default: 117 localcipher = sha1 118 ypcipher = old 119 120 root: 121 localcipher = blowfish,5 122.Ed 123.Sh SEE ALSO 124.Xr passwd 1 , 125.Xr pwhash 1 , 126.Xr pw_getconf 3 , 127.Xr passwd 5 128.Sh HISTORY 129The 130.Nm 131configuration file first appeared in 132.Nx 1.6 . 133.Pp 134The default value of 135.Sy localcipher 136was set to 137.Dq sha1 138in 139.Pa /etc/passwd.conf 140starting from 141.Nx 6.0 . 142.Pp 143The default value of 144.Sy localcipher 145was set to 146.Dq argon2id 147in 148.Pa /etc/passwd.conf 149starting from 150.Nx 10.0 . 151