Information
use_authtok - When password changing enforce the module to set the new password to the one provided by a previously stacked password module
use_authtok allows multiple pam modules to confirm a new password before it is accepted.
Solution
Note: The options specified on the pam_pwhistory.so module command line override the values from the pwhistory.conf configuration file. The pwhistory.conf file is the preferred method over configuring pam_pwhistory directly. Additionally, if both methods are used to set the same option, pwhistory may silently ignore one - only one method should be used.
Step 1 - Configure /etc/security/pwhistory.conf (preferred method):
Edit /etc/security/pwhistory.conf and add or set the use_authtok option:
use_authtok
Step 2 - Reconcile the pam-configs profile (conditional cleanup):
- IF - the pam_pwhistory profile in /usr/share/pam-configs/ has been used to configure pwhistory (i.e. a use_authtok argument is present on the pam_pwhistory.so line), remove that argument so the value in pwhistory.conf is the single source of truth. Run the following script:
#!/usr/bin/env bash
{
profiles=$(grep -Rl "pam_pwhistory.so" /usr/share/pam-configs/ || true)
for profile in $profiles; do
if grep -Pq '\h+pam_pwhistory\.so\h+([^#\n\r]+\h+)?use_authtok\b' "$profile"; then
sed -Ei '/pam_pwhistory\.so/s/\buse_authtok\b//g' "$profile"
sed -Ei 's/[[:space:]]+/ /g' "$profile"
echo "Updated pam profile: $profile"
pam-auth-update --package < /dev/null
fi
done
}
Verification:
After applying Step 1 (and Step 2 if applicable), confirm the setting is in effect:
# grep -Pi -- '^\h*use_authtok\b' /etc/security/pwhistory.conf
# grep -P -- '\bpam_pwhistory\.so\b' /etc/pam.d/common-password
The first command should return use_authtok . The second command should return the pam_pwhistory.so line without a use_authtok argument (so the pwhistory.conf value applies).