- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- NDS-LDAP password policies are not enforced by LDA...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2006 06:53 AM
11-21-2006 06:53 AM
NDS-LDAP password policies are not enforced by LDAP-UX
I'm having a problem getting my LDAP-UX client to have the password policies I've defined in Netscape Directory Server enforced.
My systems are in Trusted mode so I've copied the pam.conf.trusted to pam.conf.
I defined a password policy for userA and delibrately changed the passwordexpirationtime to some date in 2001. Whether I try with telnet or ssh to login, it lets me through without a hitch. I've enabled all logs possible and I can't see anything taht would suggest that my password's expired.
I can do an ldapsearch on my user and I can see the passwordexpirationtime value.
Shouldn't it prompt me that my password's expired?
I have NDS 6.21, LDAP-UX B.04.00.02, HP-UX 11i.
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2006 07:39 AM
11-21-2006 07:39 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
Check /etc/nsswitch.conf to see that its got ldap as the primary authentication for passwords.
Make sure the user id in question is not duplicated in /etc/passwd
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2006 07:50 AM
11-21-2006 07:50 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
# /etc/nsswitch.ldap:
#
# An example file that could be copied over to /etc/nsswitch.conf. It
# uses LDAP (Lightweight Directory Access Protocol) in conjunction with
# dns & files.
#
passwd: files ldap
group: files ldap
hosts: dns files ldap
networks: files ldap
protocols: files ldap
rpc: files ldap
publickey: ldap [NOTFOUND=return] files
netgroup: files ldap
automount: files ldap
aliases: files
services: files ldap
Also I've checked the password file and my user is not defined in it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2006 07:50 AM
11-21-2006 07:50 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2006 07:55 AM
11-21-2006 07:55 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
passwd: ldap files
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2006 07:57 AM
11-21-2006 07:57 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-28-2006 07:42 AM
11-28-2006 07:42 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
Now I'm having a problem where the system realizes that the user's password has expired, prompts me for a new password but somehow cannot change it. I get a
"Failure - LDAP processing error"
Has anybody experienced this before?
Ciao!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-28-2006 08:06 AM
11-28-2006 08:06 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
If you're not using referrals, check the access log of the Directory Server (/var/opt/netscape/servers/slapd-instance/logs/access). There may be two interesting operations, first a BIND as the user changing password where the result code should be 49 (LDAP_INVALID_CREDENTIALS), indicating the password is invalid, and if it's invalid due to being expired then a MOD operation would follow. The result code from the MOD may be interesting, for example 50 (LDAP_INSUFFICIENT_ACCESS) would indicate the user doesn't have permission to change his own password.
Don't forget that the access log is buffered by default and it may take about 30 seconds for activity to show up.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-29-2006 03:21 AM
11-29-2006 03:21 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
Thanks for your reply.
I am not using referals. But, what you are describing in the second paragraph, that's exactly what's happening. It seems that my user doesn't have access to its own password field.
But, I did the step in LDAP-UX configuration to allow self write on the all fields except uid, uidNumber, gidNumber, and homeDirectory.
What gives?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-05-2006 02:20 AM
12-05-2006 02:20 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
Has anyone heard of an ACI named "disallow_pw_change_aci"? This is the ACI that is refusing denying me password modification of users with expired passwords.
I've searched my directory tree but I haven't found it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2006 05:56 AM
12-14-2006 05:56 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
That ACI is automatically added when a global passwordChange=off password policy has been set. It should be automatically removed when the pwp setting is disabled. It sounds like it did get removed when you modified another ACI on the root entry.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2006 06:24 AM
12-14-2006 06:24 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
I finally got my password policies working although not the way I would have liked to. Apparently, the NDS software is not that stable(at least not the 6.21 version).
When I noticed that all this had something to do with ACI, I started to play around with them. So, by changing one ACI and then changing it back, the whole thing started working. (Welcome to the twilight zone)
As I like to say, I used the "Bang the side of the TV" method and it worked! I had this call opened at HP Support and they're as puzzled as I.
Anyway, I'd like to thank everybody that put in their two cents in this thread.
Cheers!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2006 06:26 AM
12-14-2006 06:26 AM
Re: NDS-LDAP password policies are not enforced by LDAP-UX
Thank you all.