On Thu 27 Aug 2026 at 14:04, Kejvan Redjamand <kejvan@chalmers.se> wrote:
False "insecure/plaintext password" warning for newly created remote user accounts: ... It seems that, some check fails for an empty string, and it is reported as "plaintext" instead of something else: no local password or externally managed password or similar.
To correct the check may probably be a simple fix, hopefully.
Thanks for another good report, Kejvan. The insecure password hash verification does indeed seem a bit too eager: It wasn't built for the case where a user account has no local password hash stored at all (i.e. just a blank string). I believe there is already an open pull request to fix this now: https://github.com/Uninett/nav/pull/4172 -- Sincerely, Morten Brekkevold Sikt – Norwegian Agency for Shared Services in Education and Research