samba-technical@lists.samba.org
[Top] [All Lists]

"Password must change" versus sambaPwdMustChange attribute

Subject: "Password must change" versus sambaPwdMustChange attribute
From: werner maes
Date: Wed, 31 Oct 2007 12:13:10 +0100
hello

I've read this thread on samba-technical (http://lists.samba.org/archive/samba-technical/2007-May/053497.html). see below
I'm running samba -3.0.25 and would like to set the password last set time.

I've tried this command: pdbedit --pwd-last-set-time="2007-10-31" --time-format="%Y-%m-%d" but it does not work.

<quote>

If you need to force it for a single user, then choose a password
last set time accordingly (zero would be fine to force it now).
</quote>


How can you do this (set the password last set time attribute using pdbedit)?
I would like to force my users to change their passwords.

kind regards

werner




On 5/24/07, Volker Lendecke <<https://lists.samba.org/mailman/listinfo/samba-technical>Volker.Lendecke at sernet.de> wrote:
>
> On Thu, May 24, 2007 at 10:28:05AM +0200, Bartlomiej Solarz-Niesluchowski
> wrote:
> > it seems that on 3.0.24 field sambaPwdMustChange has precedense
> > over  "maximum password age"
> >
> > on 3.0.25 it looks different:
> > - "maximum password age" has bigger precedence then sambaPwdMustChange
>
> This is by design. We now dynamically calculate the maximum
> password age from pwdLastChange plus account policy to match
> what NT does.
>

Yes, this is the key part: we are now doing it correctly, and we weren't
before.  If you need to force it for a single user, then choose a password
last set time accordingly (zero would be fine to force it now).

--
-------------------
Jim McDonough
Samba Team
jmcd at samba dot org



Disclaimer: http://www.kuleuven.be/cwis/email_disclaimer.htm

<Prev in Thread] Current Thread [Next in Thread>