See https://issues.asterisk.org/jira/browse/ASTERISK-18558 Index: asterisk-1.6.2.17.2/apps/app_voicemail.c =================================================================== --- asterisk-1.6.2.17.2.orig/apps/app_voicemail.c 2011-09-15 12:57:17.785252961 +0200 +++ asterisk-1.6.2.17.2/apps/app_voicemail.c 2011-09-15 12:57:20.841234237 +0200 @@ -402,6 +402,7 @@ #define MAXMSGLIMIT 9999 #define MINPASSWORD 0 /*!< Default minimum mailbox password length */ +#define ALLOWEMPTYPW 1 /*!< Default policy for allowing empty passwords */ #define BASELINELEN 72 #define BASEMAXINLINE 256 @@ -734,6 +735,7 @@ static int skipms; static int maxlogins; static int minpassword; +static int allowemptypw; /*! Poll mailboxes for changes since there is something external to * app_voicemail that may change them. */ @@ -9237,6 +9239,19 @@ if (!ast_strlen_zero(prefix)) mailbox[0] = '\0'; } + if (!allowemptypw && ast_strlen_zero(password)) { + ast_verb(3, "Empty password not allowed. User '%s' (context = %s)\n", mailbox, context ? context : "default"); + if (ast_fileexists("vm-noemptypasswords", NULL, chan->language)) { + if (ast_streamfile(chan, "vm-noemptypasswords", chan->language)) { + return -1; + } + } else { + if (ast_streamfile(chan, "vm-incorrect", chan->language)) { + return -1; + } + } + + } logretries++; if (!valid) { if (skipuser || logretries >= max_logins) { @@ -11141,6 +11156,17 @@ } } + /* Whether empty passwords are allowed */ + allowemptypw = ALLOWEMPTYPW; + if ((val = ast_variable_retrieve(cfg, "general", "allowemptypw"))) { + allowemptypw = ast_true(val); + } + if (allowemptypw) { + ast_debug(1, "Empty voicemail passwords allowed\n"); + } else { + ast_debug(1, "Empty voicemail passwords forbidden\n"); + } + /* Force new user to record name ? */ if (!(val = ast_variable_retrieve(cfg, "general", "forcename"))) val = "no"; Index: asterisk-1.6.2.17.2/configs/voicemail.conf.sample =================================================================== --- asterisk-1.6.2.17.2.orig/configs/voicemail.conf.sample 2011-09-15 17:50:44.258476698 +0200 +++ asterisk-1.6.2.17.2/configs/voicemail.conf.sample 2011-09-15 17:53:31.933531727 +0200 @@ -207,6 +207,10 @@ sendvoicemail=yes ; Allow the user to compose and send a voicemail while inside ; VoiceMailMain() [option 5 from mailbox's advanced menu]. ; If set to 'no', option 5 will not be listed. +; allowemptypw=yes ; Whether to allow empty passwords. The default behaviour is to allow them. + ; This will try to play the vm-noemptypasswords sound file as soon as vm + ; authentication is attempted and the password is empty (or '-'). It will fall + ; back to vm-incorrect if that file is not available. ; searchcontexts=yes ; Current default behavior is to search only the default context ; if one is not specified. The older behavior was to search all contexts. ; This option restores the old behavior [DEFAULT=no]