Comment 5 for bug 656004

Revision history for this message
Colin Watson (cjwatson) wrote :

I realise the policy is slightly different, and ideally we'd run the password through PAM to see what it says, but unfortunately this isn't possible because the user doesn't exist yet when we're asking the question and so you can't ask PAM to set its password - we did look at this when implementing the "weak password" warnings in the installer and it wasn't feasible. Thus, the installer does its own checks.

In d-i, I have no problem with it being *possible* to force a weak passphrase in all the contexts you mention, although you should always get a warning dialog. Please confirm whether this was the case.

The other issues here seem to be:

 * Ubiquity's KDE frontend doesn't show password warnings
 * Wubi has no password checks
 * Perhaps some passwords should be rejected in Ubiquity rather than merely producing warnings