Michael,
Thank you for your reply.
I made several attempts to configure slapo-policy but I’m not able to get it to work.
I gathered online documentation and did the following on my openldap 2.4.39 RHEL7 server to enable slapo-ppolicy:
Any advice will be greatly appreciated.
Thank you,
Liz
From: Michael Ströder <michael@stroeder.com>
Date: Friday, September 18, 2015 at 9:27 AM To: Elizabeth Real Chavez <Elizabeth.Real@jpl.nasa.gov>, "openldap-technical@openldap.org" <openldap-technical@openldap.org> Subject: Re: Allow users to change ldap password with passwd Real, Elizabeth (392K) wrote:
Use OpenLDAP's slapo-ppolicy instead!
Using shadow account attributes is deprecated since years.
This sounds more like PAM and sssd related. So you should sort this out first
- maybe by asking for specific issues on sssd-users mailing list.
Think twice! You should not do that because of security issues!
If you really insist on using shadow account attributes you have to use
slapo-smbk5pwd to let slapd set them internally when receiving a Password
Modify extended operation.
Ciao, Michael.
|