Re: reset AD user password when account is expired

Bruce Johnson <[email protected]> Fri, 21 Nov 2014 21:36:27 +0000
Newsgroups gmane.comp.lang.perl.modules.ldap
Message-ID <[email protected]>
--_000_0CE54B9EE4384A62BC81B9AB16B7F3E7pharmacyarizonaedu_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable


On Nov 21, 2014, at 2:19 PM, Natxo Asenjo <[email protected]<mailto:na=
[email protected]>> wrote:

hi,

using code like in the FAQ it is really simple to change the password
of an AD user.

Unfortunately, once the account is already expired I get this error:

80090308: LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext
error, data 773, v1db1

There=92s this thread at perlmonks that might help:

<http://www.perlmonks.org/?node_id=3D751018>

Shorter: You can=92t do it with LDAP; you have to do it via Kerberos.

--
Bruce Johnson
University of Arizona
College of Pharmacy
Information Technology Group

Institutions do not have opinions, merely customs


--_000_0CE54B9EE4384A62BC81B9AB16B7F3E7pharmacyarizonaedu_
Content-Type: text/html; charset="Windows-1252"
Content-ID: <[email protected]>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-lin=
e-break: after-white-space;">
<br>
<div>
<div>On Nov 21, 2014, at 2:19 PM, Natxo Asenjo &lt;<a href=3D"mailto:natxo.=
[email protected]">[email protected]</a>&gt; wrote:</div>
<br class=3D"Apple-interchange-newline">
<blockquote type=3D"cite">hi,<br>
<br>
using code like in the FAQ it is really simple to change the password<br>
of an AD user.<br>
<br>
Unfortunately, once the account is already expired I get this error:<br>
<br>
80090308: LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext<br>
error, data 773, v1db1<br>
</blockquote>
<br>
</div>
<div>There=92s this thread at perlmonks that might help:</div>
<div><br>
</div>
<div>&lt;<a href=3D"http://www.perlmonks.org/?node_id=3D751018">http://www.=
perlmonks.org/?node_id=3D751018</a>&gt;</div>
<div><br>
</div>
<div>Shorter: You can=92t do it with LDAP; you have to do it via Kerberos.<=
/div>
<br>
<div>--&nbsp;<br>
Bruce Johnson<br>
University of Arizona<br>
College of Pharmacy<br>
Information Technology Group<br>
<br>
Institutions do not have&nbsp;opinions, merely customs </div>
<br>
</body>
</html>

--_000_0CE54B9EE4384A62BC81B9AB16B7F3E7pharmacyarizonaedu_--