> On 8 Mar 2019, at 14:50, Gordon Messmer <gordon.messmer@xxxxxxxxx> wrote: > > On 3/7/19 1:11 PM, Janet H wrote: >> I want to be able to change the LDAP password (userPassword) and have that then update the sambaNTPassword. > > > I believe FreeIPA (which is built on 389 DS) will do that when you install it with "--setup-adtrust” > It uses the ipaNTHash field, and I don’t know if it’s in a samba compatible format. Samba with IPA uses krb5 for security generally rather than reading the NT hash IIRC. — Sincerely, William Brown Software Engineer, 389 Directory Server SUSE Labs _______________________________________________ 389-users mailing list -- 389-users@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to 389-users-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/389-users@xxxxxxxxxxxxxxxxxxxxxxx