Displaying 20 results from an estimated 330 matches for "sambapwdmustchange".
2004 Jan 08
2
Hows samba calculating sambaPwdMustChange?
When samba password has been expired, user are force to change their password from client WS.
Samba will modify sambaPwdMustChange attribute and the value seems always "2147483647", this not happen when changin password with smbpasswd.
>From where samba calculate value for "sambaPwdMustChange"? is it constant?
Is it possible to specify different value?
Tks.
2006 Oct 04
2
Windows client does not recognize password change...
...correct case."
But the kicker is that the PDC *did* change both Linux and Windows
passwords; the client machine is saying there's an error when the
password was changed.
According to the log file for the machine, it looks like it may have
failed because it couldn't find the "sambaPwdMustChange" attribute. But
using a LDAP browser, I see that the "sambaPwdMustChange" is there.
Any suggestions on how to fix this or what the problem may be?
Thank you!
Jason
[2006/10/04 13:13:00, 5]
passdb/secrets.c:secrets_fetch_trusted_domain_password(325)
secrets_fetch failed!
[2...
2009 Aug 28
2
sambaPwdMustChange not synced on PDC from BDC
Hi
I have a PDC/BDC samba/ldap environment.
PDC:
samba 3.0.24
slapd 2.3.30
BDC:
samba 3.2.5
slapd 2.4.11
Ldap replication is working fine, but I have noticed two issues
1- when a windows user change password on BDC, sambaPwdMustChange and
sambaPwdCanChange is not synced on PDC
(using ldap passwd sync = yes and unix password sync = no)
2- when using 'net sam set pwdmustchange' on PDC, sambaPwdCanChange is not
synced on BDC
Anyone can point me what's wrong?
About issue 1- , I can use unix password sync = yes a...
2005 Jan 17
2
sambaPwdMustChange
Hi,
i have samba 3.0.10 installed with LDAP.
I noticed few days ago that my adminsitrator account has expired. I
think it's because of the sambaPwdMustChange field of LDAP. I changed
the passwd now i have the value 1108741705 in it. What does it mean
(when will i be prompted again to change my passwd) and do i have to put
in this field so that the password will never expire ?
Thanks for any help
2008 Feb 20
1
sambaPwdMustChange attribute didn't get updated (3.0.27a)
...tObservationWindow
sambaLockoutThreshold
sambaForceLogoff
sambaRefuseMachinePwdChange
But one problem still exists:
If Windows-users change their password via the normal Windows dialog,
the password got changed in LDAP , also the sambaLastChange attribute
got updated , BUT sambaPwdCanChange and sambaPwdMustChange attributes
didn't update and so all the Maximum Password Age stuff, including
remind users of their password expiration and force user to change their
password if expire didn't work anymore.
I can't find any other maybe access right problems within ldap, so why
the sambaPwdMustCh...
2003 Jun 20
1
what is the default amount of time that smbpasswd increments the sambaPwdMustChange value
So I get a phone call about my companie's controler not being able to
log into samba. About two weeks ago we migrated from Win2k Server to
Samba running on LDAP. What would be the default value that
sambaPwdMustChange would be incremented? This is NT Time Right (1 unit
for every 100 ms from 1600 right?)
I just had to bump everybody what I'm guessing is three weeks, but I
need to know soon so I don't get woken up out of bed again!
-------------- next part --------------
A non-text attachment was scrub...
2004 Sep 29
0
sambaPwdMustChange not properly set with smbldap
I'm using samba 3.0.6 on fedora core 1 with LDAP enabled and smbldap-tools.
When I change a user password with smbldap-passwd <username>, i find that
sambaPwdMustChange attribute is correctly set to 30 days later as set in
smbldap_conf.
But, if I try to change password from any Win2000 or WinXP client with
CTRL+ALT+CANC --> CHANGE PASSWORD i notice that sambaPwdMustChange attribute is
always set to 2147483647.
I have tryed different setups in smb.conf but not...
2008 Oct 09
2
sambaPwdLastSet=0 vs sambaPwdMustChange=0
Hi all,
Something is unclear to me, maybe someone here can explain.
I want to users to get the "you are required to change your password"
dialogue, when they logon for the first time.
According to the documentation setting sambaPwdMustChange=0 should work.
However, on my setup, it does NOT work. The user can log on, but is NOT
asked to change his or her password.
(docs:
http://www.samba.org/samba/docs/man/Samba-HOWTO-Collection/passdb.html#id2586078)
Then I tried using "net sam set pwdmustchangenow USERNAME yes" (which is...
2009 Mar 13
1
PAM_WINBIND problem with sambaPwdMustChange
Hi People!
I use pam_winbind for authentication in my computer workstation using
Debian Lenny 5.0, Stable Version.
I configure my user with this option "sambaPwdMustChange: 0", and I
logon in GDM without asking to change password. Who knows what can be?
I use Samba PDC with Heimdal Kerberos, but, I configure PAM with only
pam_winbind for tests...
Client versions:
ii libwbclient0 2:3.2.5-4
client library for interfacing with winbind...
2011 Jun 20
0
Remove obsolete sambaPwdMustChange and sambaKickoffTime from LDAP database
Dear Samba friends,
>From the information I have found on the internet, I understood that
sambaPwdMustChange and sambaLogoffTime are obsolete. When there is no use
for these attributes in the future, I would recommend to remove them from
the samba scheme. What would be the procedure to follow to remove these
attributes and to update the ldap database?
--
Met vriendelijke groeten,
With kind regards,
Mit...
2013 Oct 18
0
sambaPwdLastSet and sambaPwdMustChange - major issue
...Separate System)
samba-3.6.3-0.18.3
SLES - 10 (For LDAP Backend, Separate System)
openldap2-2.3.19-18.7
The above setup is working fine and the password policies are all fine.
Problem - If the user changes the password at the Windows Client sambaPwdLastSet changes date to the new date
but the sambaPwdMustChange does not change to the next date, ie (sambaPwdLastSet + 90 Days).
If the password is set in the command line by the administrator then everything is fine.
How do I fix this issue, Please advise.
Thanks
AVIN
2004 Sep 15
4
Samba3 + smbldap-tools & smbpasswd
...ddling lately with Samba 3 coupled with openldap, nss_ldap,
pam_ldap and the smbldap-tools to create a PDC.
Following various examples, most things work, but I have an issue with
changing passwords from Windows.
If I manually change a password with smbldap-passwd, the script
correctly adjusts the sambaPwdMustChange attribute according to what
defaultMaxPasswordAge is set to.
If I change the password through Windows, Samba presumably uses
smbpasswd, because the sambaPwdMustChange attribute is then somehow set
to only 2 days into the future. The same thing happens if I run
smbpasswd manually. As a simple hack...
2007 Aug 13
0
ldap passwd sync on 3.0.25a
...Success (0)
My OpenLDAP auditlog file confirms that smbk5pwd is working:
# modify 1187006837 o=stars cn=sambamgr,ou=Managers,o=stars
dn: uid=lacoste,ou=Users,ou=Accounts,o=stars
changetype: modify
replace: userPassword
userPassword:: e1NTSEF9UFZSZk1zcTNoRlFuYWhGMzRWN1BZWE5BU3U0MHNVTWo=
-
replace: sambaPwdMustChange
sambaPwdMustChange: 1218542837
-
replace: sambaPwdLastSet
sambaPwdLastSet: 1187006837
-
replace: sambaLMPassword
sambaLMPassword: 8d16f4badd1da493aad3b435b51404ee
-
replace: sambaNTPassword
sambaNTPassword: b39a61f16a4e11fa80580241f1d4aae8
-
replace: pwdChangedTime
pwdChangedTime: 20070813120717Z
-...
2004 Mar 15
1
smbpasswd trying to add instead of replace attribut
...quot;MOD" from log file (from different domain) :
UNSUCESSFULL
Mar 15 17:10:53 hurricane slapd[27056]: conn=29489 op=1 MOD dn="uid=pwreka,ou=people,ou=purwakarta,dc=indorama,dc=com"
Mar 15 17:10:53 hurricane slapd[27056]: conn=29489 op=1 MOD attr=sambaPwdCanChange sambaPwdCanChange sambaPwdMustChange samb
aPwdMustChange sambaLMPassword sambaNTPassword sambaPwdLastSet sambaPwdLastSet
Mar 15 17:10:53 hurricane slapd[27056]: Entry (uid=pwreka,ou=people,ou=purwakarta,dc=indorama,dc=com), attribute 'sambaLMPas
sword' cannot have multiple values
Mar 15 17:10:53 hurricane slapd[27056]: entry f...
2004 Jun 07
2
Password trouble with LDAP (eDirectory)
Hi All,
I have a strange problem with passwords, stored in LDAP.
When i try to logon as a user with the correct password, access is
denied and the log says
check_ntlm_password: Authentication for user [administrator] ->
[administrator] FAILED with error NT_STATUS_NO_SUCH_USER
When i try to logon a user with incorrect password, access is (of
course) denied, but the log now says
2003 Dec 11
1
Forcing Users to change passwords.
...; -C 9
# password age 90 days
$ pdbedit -P "maximum password age" -C 7776000
Samba takes age in seconds, so 60*60*24*90, is what you need.
Remember, that the user has to change his/her password from workstation
once, then policy takes effect. Another way is to manually change users
"sambaPwdMustChange" value to "0", so user is forced to change password on
next logon. After password change, new "sambaPwdMustChange" will be set,
with timestamp 90 days forward.
$ pdbedit -P "password history" -C 3
Doesn't work. Andrew said, it isn't implemented yet. Samba...
2007 Jul 17
2
[Urgent] Cannot make changes via pdbedit
...If I run pdbedit -Lv -u jrolfe, I get:
Password last set: Mon, 01 Jan 2007 03:00:00 EST
Password can change: Mon, 08 Jan 2007 03:00:00 EST
Password must change: never
If I run ../smbldap-usershow jrolfe, I get:
sambaPwdCanChange: 1183795200
sambaPwdLastSet: 1167638400
sambaPwdMustChange: 1167638400
The unix times converted to english are: Sat, 07 Jul 2007 08:00:00 GMT
and Mon, 01 Jan 2007 08:00:00 GMT. So you can see that the dates do not
match between pdbedit and smbldap-tools.
This is really causing a problem because I am trying to set up a new
user and cannot get his passwo...
2005 Jun 04
3
smbldap-tools and joining workstation to domain
...RG
objectClass: top
objectClass: posixAccount
objectClass: sambaSAMAccount
cn: testhost3$
gidNumber: 553
homeDirectory: /dev/null
loginShell: /bin/false
uid: testhost3$
uidNumber: 1005
sambaPwdLastSet: 0
sambaLogonTime: 0
sambaLogoffTime: 2147483647
sambaKickoffTime: 2147483647
sambaPwdCanChange: 0
sambaPwdMustChange: 2147483647
description: Computer Account
rid: 0
primaryGroupID: 0
lmPassword: 7582BF7F733351347D485E46C8E6306E
ntPassword: 7582BF7F733351347D485E46C8E6306E
acctFlags: [W ]
Looking at smbldap-useradd script code I can see that sambaSAMAccount
entrys are only added when -i switch is used...
2005 Jun 10
2
samba ldap problem
...root, people, example.com
dn: uid=root,ou=people,dc=example,dc=com
uid: root
sambaSID: S-1-5-21-3527759599-3696857034-3584459987-500
sambaPrimaryGroupSID: S-1-5-21-3527759599-3696857034-3584459987-512
displayName: root
sambaAcctFlags: [U ]
objectClass: account
objectClass: sambaSamAccount
sambaPwdMustChange: 2147483647
sambaLMPassword: 63D2114DE42F744B30A84C4AFE5AFFFF
sambaNTPassword: 5460FB29D247C383F63E1E3A417FC39B
sambaPasswordHistory: 00000000000000000000000000000000000000000000000000000000
00000000
sambaPwdCanChange: 1118395221
sambaPwdLastSet: 1118395221
# win2k$, Computers, example.com
dn: ui...
2004 Jul 05
1
Accounts are getting disabled
...lass: person
objectClass: organizationalPerson
objectClass: top
objectClass: sambaSamAccount
cn: alexander-cristea
sn: alexander-cristea
uid: alexander-cristea
homeDirectory: /home/kl-1g3/alexander-cristea
gecos: "kl-1g3"
loginShell: /bin/sh
shadowMin: 1
shadowMax: 99999
shadowWarning: 14
sambaPwdMustChange: 1800000000
gidNumber: 112
sambaPrimaryGroupSID: S-1-5-21-3371203057-3264423045-2392767973-1225
uidNumber: 5248
sambaSID: S-1-5-21-3371203057-3264423045-2392767973-11496
sambaProfilePath: \\WILMA2\profile
sambaAcctFlags: [UX ]
The same user monday morning:
# alexander-cristea, kl-1g3, peopl...