[389-users] ldappasswd and shadowLastChange attribute

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I finally figured out a working shell script to make LDAP user password 
changes using mozldap/ldappasswd.  Unfortunately, I just discovered that 
changing the password using this does not update the "shadowLastChange" 
attribute, so users with expired passwords are still not able to log in, 
even after an admin has reset their password in this manner.

Since we are migrating from traditional shadow passwords to LDAP, the 
attribute we need to get updated by this is "shadowLastChange"

I attempted to work around this in /etc/ldap.conf by adding this:

nss_map_attribute shadowLastChange pwdLastSet

But to no avail.  In addition, the "change ldap password" plugin also does 
not update this, although webmin users and groups module does.

What am I missing?  Thanks in Advance!

James Smallacombe		      PlantageNet, Inc. CEO and Janitor
up@xxxx							    http://3.am
=========================================================================
--
389 users mailing list
389-users@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/389-users


[Index of Archives]     [Fedora Directory Users]     [Fedora Directory Devel]     [Fedora Announce]     [Fedora Legacy Announce]     [Kernel]     [Fedora Legacy]     [Share Photos]     [Fedora Desktop]     [PAM]     [Red Hat Watch]     [Red Hat Development]     [Big List of Linux Books]     [Gimp]     [Yosemite News]

  Powered by Linux