RE: dirsrv, SSH and forcing password change at first login

Joe Friedeggs <[email protected]>
Newsgroups gmane.linux.pam
Message-ID <[email protected]>
I had the same issue on Red Hat (see https://www.redhat.com/archives/pam-list/2009-October/msg00031.html).  I found a couple of work-arounds, but the ultimate solution was set the following in /etc/ldap.conf (nss/pam ldap config):



pam_password exop



Thanks,
Joe

Date: Tue, 27 Sep 2011 15:24:51 +0200
Subject: dirsrv, SSH and forcing password change at first login
From: [email protected]
To: [email protected]

Hi all,

I've got four LDAP servers up and running in multi-master configuration. Everything works fine, including ACIs, password policies, but I've got a problem in forcing users to change their passwords at first successful login.

I tried both methods "passwordMustChange: on" on the Password Policy Container and "passwordExpirationTime: 19700101000000Z" as attribute and value of the user, but with no luck. User is still able to login even after a password reset.

I tried to Google for this problem - of course! - I made some modification to PAM subsystem, (pam.d/* configuration files), nsswitch.conf and sshd_config, (challenge-response auth). 
I even tried to dig for some useful and unknown to me PAM module, but nothing did the trick, so I reverted everything to the original configuration.

I'm sure the Password Policy works because if I try to forcibly change my password as an LDAP SSH-connected user - with passwd - it applies all the checks I setup in Password Policy, (syntax and all the rest). But why, then, this particular feature doesn't work?

Please can you give me a clue, if you have it? :)
PAM/NSS could be the responsible?

Here are some specs of the software used:

RHEL Server 5.4 "Tikanga"
Kernel 2.6.18-164.el5
DS 8.2.0-2

PAM, SSHD, and all the rest are factory-default in Tikanga :)



Thanks
Claudio


_______________________________________________
Pam-list mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/pam-list

_______________________________________________
Pam-list mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/pam-list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.