Will it make sense to switch to or merge with the passwd(1) implementation from Shadow, which Debian is using? Are there features in this implementation that Shadow is missing?
passwd(1)
The Fedora Git history gets lost in the weeds of the transition from CVS 18 years ago, so it's hard for me to say from the outside.
At least in recent times, Fedora contributors have been able to get changes into Shadow and it does look actively maintained. Even then, it's possible that it might be missing important features that matter to us. That's why I am asking.
I spoke to @nalin , who was a prolific contributor to this passwd(1) implementation long ago, yesterday. He didn't remember the exact specifics of why Fedora chose a different implementation, but he was open to the idea of switching or merging if there are no missing features.