--- pam_ccreds-10-orig/README 2009-04-02 21:39:32.000000000 -0400 +++ pam_ccreds-10/README 2009-09-28 11:26:26.000000000 -0400 @@ -54,6 +54,12 @@ following module options are also recogn The "cc_test" and "cc_dump" utilities are also provided; cc_dump may be removed in a future version. +The "ccreds_chkpwd" setuid helper provides ccreds db checking for +non-root users. It will allow checking password of the caller user +only so passwords of other users cannot be brute forced this way. +Note also that the ccredsfile option of the module is ignored when +the helper is called and the default file is used. + Things we need to do are: o more testing