With sssd, using "shadowAccount(shadowExpire 0)" at and pwdpolicy on the LDAP-server does not work
Issue
Please tell us the reason and the workaround that "shadowAccount(shadowExpire 0)" is not beeing honoured, when both "shadowAccount(shadowExpire 0)" and "PwdPolicy" are configured on a LDAP-server. The user with a LDAP account can nontheless login.
nslcd
is behaving differently: also when a server side password policy is configured, nslcd
is considering shadowExpire on the client.
Environment
- Red HAt Enterprise Linux (RHEL) 7
- SSSD
- LDAP
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.