Using standard NIS commands normal users can obtain a full list of hashed passwords. How do I prevent this?
Issue
If any user runs the following commands:
getent passwd
ypcat passwd.adjunct.byname
they get the hashed password of every user. They can then run cracking tools against the hashed passwords, which can be seen as a potential security issue.
Environment
All versions of Red Hat Enterprise Linux configured to use NIS for authentication.
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.