Сравнивайте с английским: нажмите на абзац — оригинал откроется в окне. Кнопка EN под абзацем показывает его прямо в тексте.
Введение
Инструмент для смены паролей в Unix-подобных ОС
Tool to change passwords on Unix like OSes
`passwd` – это команда в Unix, Plan 9, Inferno и большинстве Unix-подобных операционных систем, используемая для смены пароля пользователя. Введенный пользователем пароль проходит через функцию выработки ключа для создания хешированной версии нового пароля, которая и сохраняется. Сохраняется только хешированная версия; введенный пароль не сохраняется из соображений безопасности. При входе пользователя в систему, введенный им пароль также проходит через ту же функцию выработки ключа, и полученная хешированная версия сравнивается с сохраненной. Если хеши совпадают, введенный пароль считается верным, и пользователь аутентифицируется. Теоретически, два разных пароля могут давать один и тот же хеш. Однако криптографические хеш-функции разработаны таким образом, что найти любой пароль, дающий тот же хеш, крайне сложно и практически невозможно, поэтому, если полученный хеш совпадает с сохраненным, пользователь может быть аутентифицирован. Команда `passwd` может использоваться для смены паролей локальных учетных записей, а также, в большинстве систем, для смены паролей, управляемых в распределенных механизмах аутентификации, таких как NIS, Kerberos или LDAP.
passwd is a command on Unix, Plan 9, Inferno, and most Unix like operating systems used to change a user's password. The password entered by the user is run through a key derivation function to create a hashed version of the new password, which is saved. Only the hashed version is stored; the entered password is not saved for security reasons. When the user logs on, the password entered by the user during the log on process is run through the same key derivation function and the resulting hashed version is compared with the saved version. If the hashes are identical, the entered password is considered to be correct, and the user is authenticated. In theory, it is possible for two different passwords to produce the same hash. However, cryptographic hash functions are designed in such a way that finding any password that produces the same hash is very difficult and practically infeasible, so if the produced hash matches the stored one, the user can be authenticated. The passwd command may be used to change passwords for local accounts, and on most systems, can also be used to change passwords managed in a distributed authentication mechanism such as NIS, Kerberos, or LDAP.
История
До появления механизма затенения паролей, хешированный пароль пользователя Unix хранился во втором поле записи в файле /etc/passwd (в формате, состоящем из семи полей, как описано выше). Механизм затенения паролей впервые появился в системах Unix с разработкой SunOS в середине 1980-х годов, System V Release 3.2 в 1988 году и BSD4.3 Reno в 1990 году. Однако, поставщики, выполнявшие портирование из более ранних версий UNIX, не всегда включали новые функции затенения паролей в свои сборки, оставляя пользователей этих систем уязвимыми для атак на файлы паролей. Системные администраторы также могут настроить хранение паролей в распределенных базах данных, таких как NIS и LDAP, вместо файлов на каждой подключенной системе. В случае с NIS, механизм теневого пароля часто по-прежнему используется на серверах NIS; в других распределенных механизмах проблема доступа к различным компонентам аутентификации пользователя решается механизмами безопасности базового хранилища данных. В 1987 году автор оригинального пакета Shadow Password Suite, Джули Хоу, подверглась взлому компьютера и написала первую версию Shadow Suite, включающую команды login, passwd и su. Первая версия, разработанная для операционной системы SCO Xenix, быстро была портирована на другие платформы. Shadow Suite был портирован на Linux в 1992 году, через год после первоначального объявления о проекте Linux, и был включен во многие ранние дистрибутивы, и продолжает включаться во многие современные дистрибутивы Linux. Ранее для изменения паролей в различных схемах аутентификации требовались разные команды. Например, команда для изменения пароля NIS была yppasswd. Это требовало от пользователей знания различных методов изменения паролей для разных систем, а также приводило к неэффективному дублированию кода в различных программах, выполняющих одни и те же функции с разными бэк-эндами. В большинстве реализаций теперь используется единая команда passwd, а управление тем, где фактически изменяется пароль, осуществляется прозрачно для пользователя посредством подключаемых модулей аутентификации (PAM). Например, тип используемого хеша определяется конфигурацией модуля pam_unix.so. По умолчанию использовался хеш MD5, в то время как современные модули также поддерживают более надежные хеши, такие как blowfish, SHA256 и SHA512.
Prior to password shadowing, a Unix user's hashed password was stored in the second field of their record in the /etc/passwd file (within the seven field format as outlined above). Password shadowing first appeared in Unix systems with the development of SunOS in the mid 1980s, System V Release 3.2 in 1988 and BSD4.3 Reno in 1990. But, vendors who had performed ports from earlier UNIX releases did not always include the new password shadowing features in their releases, leaving users of those systems exposed to password file attacks. System administrators may also arrange for the storage of passwords in distributed databases such as NIS and LDAP, rather than in files on each connected system. In the case of NIS, the shadow password mechanism is often still used on the NIS servers; in other distributed mechanisms the problem of access to the various user authentication components is handled by the security mechanisms of the underlying data repository. In 1987, the author of the original Shadow Password Suite, Julie Haugh, experienced a computer break in and wrote the initial release of the Shadow Suite containing the login, passwd and su commands. The original release, written for the SCO Xenix operating system, quickly got ported to other platforms. The Shadow Suite was ported to Linux in 1992 one year after the original announcement of the Linux project, and was included in many early distributions, and continues to be included in many current Linux distributions. In the past, it was necessary to have different commands to change passwords in different authentication schemes. For example, the command to change a NIS password was yppasswd. This required users to be aware of the different methods to change passwords for different systems, and also resulted in wasteful duplication of code in the various programs that performed the same functions with different back ends. In most implementations, there is now a single passwd command, and the control of where the password is actually changed is handled transparently to the user via pluggable authentication modules (PAMs). For example, the type of hash used is dictated by the configuration of the pam unix. so module. By default, the MD5 hash has been used, while current modules are also capable of stronger hashes such as blowfish, SHA256 and SHA512.