6.6. Managing Password Synchronization
6.6.1. Setting up the Windows Server for Password Synchronization
- Active Directory must be running in SSL.
NoteInstall the Microsoft Certificate System in Enterprise Root Mode. Active Directory will then automatically enroll to retrieve its SSL server certificate.
- The Password Synchronization Service must be installed on each Active Directory domain controller. To synchronize a password from Windows, the PassSync service requires access to the unencrypted password to synchronize it over a secure connection to IdM. Because users can change their passwords on every domain controller, the installation of the PassSync service on each domain controller is necessary.
- The password policy must be set similar on IdM and Active Directory side. When the synchronization destination receives an updated password, it was only validated to match the policy on the source. It is not re-validated on the synchronization destination.
> dsquery * -scope base -attr pwdProperties pwdProperties 1
pwdPropertiesis set to
1, the password complexity policy is enabled for the domain.
gpmc.mscfrom the command line.
- Open→ → .
- Right-click theentry and select .
Group Policy Management Editoropens automatically.
- Open→ → → → → .
- Enable the
Password must meet complexity requirementsoption and save.
6.6.2. Setting up Password Synchronization
- Download the
PassSync.msifile to the Active Directory machine.
- Log in to the Customer Portal.
- Click the Downloads link in the upper left corner.
- Select Red Hat Enterprise Linux.
- Select the most recent version of Red Hat Enterprise Linux 6 or Red Hat Enterprise Linux 7 and architecture.
- Download PassSync Installer by clicking on the 'Download Now' button.
NoteRegardless of the Red Hat Enterprise Linux architecture, there are two PassSync packages available, one for 32-bit Windows servers and one for 64-bit. Make sure to select the appropriate packages for your Windows platform.
- Double-click the Password Synchronization MSI file to install it.
- The Password Synchronrization Setup window appears. Hit Next to begin installing.
- Fill in the information to establish the connection to the IdM server.
Hit, then to install Password Synchronization.
- The IdM server connection information, including the host name and secure port number.
- The user name of the system user which Active Directory uses to connect to the IdM machine. This account is configured automatically when synchronization is configured on the IdM server. The default account is
- The password set in the
--passsyncoption when the synchronization agreement was created.
- The search base for the people subtree on the IdM server. The Active Directory server connects to the IdM server similar to an
ldapsearchor replication operation, so it has to know where in the IdM subtree to look for user accounts. The user subtree is
- The certificate token is not used at this time, so that field should be left blank.
- Import the IdM server's CA certificate into the PassSync certificate store.
- Download the IdM server's CA certificate from
- Copy the IdM CA certificate to the Active Directory server.
- Install the IdM CA certificate in the Password Synchronization database. For example:
cd "C:\Program Files\Red Hat Directory Password Synchronization" certutil.exe -d . -A -n "IPASERVER.EXAMPLE.COM IPA CA" -t CT,, -a -i ipaca.crt
- Reboot the Windows machine to start Password Synchronization.
NoteThe Windows machine must be rebooted. Without the rebooting,
PasswordHook.dllis not enabled, and password synchronization will not function.
- If passwords for existing accounts should be synchronized, reset the user passwords.
NoteThe Password Synchronization client captures password changes and then synchronizes them between Active Directory and IdM. This means that it synchronizes new passwords or password updates.Existing passwords, which are stored in a hashed form in both IdM and Active Directory, cannot be decrypted or synchronized when the Password Synchronization client is installed, so existing passwords are not synchronized. User passwords must be changed to initiate synchronization between the peer servers.
admingroup. This is an intended behavior to prevent, for example, password synchronization agents or low level user administrators to change passwords of top level administrators.