I'm curious whether anyone else has a customization like this and if so whether they've run into a similar problem, and if so [horrible sentence ;-] how they overcame it.
Original System: TS 5.5.2 / Solaris 8 / Expect v. 5.37.2
New System: TS 6.5.0 / Solaris 9 / Expect v. 5.39.0 (and now back to 5.37.2)
We have a custom menu item for allowing users to change their password on the TS server.
The original code had a CGI script that prompted for the existing password [P1], the new password [P2], and a confirmation of the new password [P3] and then on-submit of the form, exec'd an Expect script which did some preliminary testing of the values provided (e.g., all parameters have values, P2 == P3, length(P2) > 5, etc.), and then it:
- Spawns /usr/bin/passwd
-- waits for "Enter existing login password: "
- sends P1
-- waits for either:
--+ "New Password: ", or
--+ "passwd: Sorry, wrong passwd"
If we got the latter - we bomb out. If we got the former ...
- we continue by sending P2 and looking for:
-- "Re-enter new Password: "
-- "one numeric or special character."
-- "must be at least 6 characters"
-- "differ by at least 3 positions"
Unless we get the first one, we abort. If we get the first one, we send P3 and verify that we get:
- "passwd: password successfully changed for"
back from the system - and then everyone is happy - yippie, yahooie, etc.
On the old system - this seemed to work fine.
On the new system, originally with a newer version of expect - it seemed to work for changing some passwords, but if your original password contained an '@' it failed; saying "passwd: Sorry, wrong passwd"
So I started looking at Expect.pm -- a perl module for working with Expect -- and I put together a fairly nice script for doing all this and ran it from the command line and it worked just fine.
I plugged the same code into the CGI code for the custom menu item - and now it doesn't matter *what* password you use for P1 - it fails when running from a custom menu item with "passwd: Sorry, wrong passwd" - but works just fine when run from the command line.
I've turned on debugging and as near as I can tell it doesn't matter which way I run it - the same text is getting sent to the spawned /usr/bin/passwd process - but it doesn't work when coming from a CGI while it does work when coming from the command line.
If anyone has some ideas - I'm interested in hearing them.
--fish
Senior Consultant, Quotient Inc.
http://www.quotient-inc.com