Information
use_authtok - When password changing enforce the module to set the new password to the one provided by a previously stacked password module
use_authtok allows multiple pam modules to confirm a new password before it is accepted.
Solution
Edit or add the following line in /etc/security/pwhistory.conf :
use_authtok
- OR/IF - The pam_pwhistory profile in /usr/share/pam-configs/ has been used to configure pwhistory . Run the following script to remove the use_authtok argument to the pam_pwhistory line in the Password section:
#!/usr/bin/env bash
{
profiles=$(grep -Rl "pam_pwhistory.so" /usr/share/pam-configs/ || true)
for profile in $profiles; do
if grep -Pq '\h+pam_pwhistory\.so\h+([^#\n\r]+\h+)?use_authtok\b' "$profile"; then
sed -Ei '/pam_pwhistory\.so/s/\use_authtok\b//g' "$profile"
sed -Ei 's/[[:space:]]+/ /g' "$profile"
echo "Updated pam profile: $profile"
pam-auth-update --package < /dev/null
fi
done
}
Note : The options specified on the pwhistory.so module command line override the values from the pwhistory.conf configuration file. The pwhistory.conf file is the preferred method over configuring pam_pwhistory directly.