search for: sambapwdmustchange

Displaying 20 results from an estimated 330 matches for "sambapwdmustchange".

2004 Jan 08
2
Hows samba calculating sambaPwdMustChange?
When samba password has been expired, user are force to change their password from client WS. Samba will modify sambaPwdMustChange attribute and the value seems always "2147483647", this not happen when changin password with smbpasswd. >From where samba calculate value for "sambaPwdMustChange"? is it constant? Is it possible to specify different value? Tks.
2006 Oct 04
2
Windows client does not recognize password change...
...correct case." But the kicker is that the PDC *did* change both Linux and Windows passwords; the client machine is saying there's an error when the password was changed. According to the log file for the machine, it looks like it may have failed because it couldn't find the "sambaPwdMustChange" attribute. But using a LDAP browser, I see that the "sambaPwdMustChange" is there. Any suggestions on how to fix this or what the problem may be? Thank you! Jason [2006/10/04 13:13:00, 5] passdb/secrets.c:secrets_fetch_trusted_domain_password(325) secrets_fetch failed! [2...
2009 Aug 28
2
sambaPwdMustChange not synced on PDC from BDC
Hi I have a PDC/BDC samba/ldap environment. PDC: samba 3.0.24 slapd 2.3.30 BDC: samba 3.2.5 slapd 2.4.11 Ldap replication is working fine, but I have noticed two issues 1- when a windows user change password on BDC, sambaPwdMustChange and sambaPwdCanChange is not synced on PDC (using ldap passwd sync = yes and unix password sync = no) 2- when using 'net sam set pwdmustchange' on PDC, sambaPwdCanChange is not synced on BDC Anyone can point me what's wrong? About issue 1- , I can use unix password sync = yes a...
2005 Jan 17
2
sambaPwdMustChange
Hi, i have samba 3.0.10 installed with LDAP. I noticed few days ago that my adminsitrator account has expired. I think it's because of the sambaPwdMustChange field of LDAP. I changed the passwd now i have the value 1108741705 in it. What does it mean (when will i be prompted again to change my passwd) and do i have to put in this field so that the password will never expire ? Thanks for any help
2008 Feb 20
1
sambaPwdMustChange attribute didn't get updated (3.0.27a)
...tObservationWindow sambaLockoutThreshold sambaForceLogoff sambaRefuseMachinePwdChange But one problem still exists: If Windows-users change their password via the normal Windows dialog, the password got changed in LDAP , also the sambaLastChange attribute got updated , BUT sambaPwdCanChange and sambaPwdMustChange attributes didn't update and so all the Maximum Password Age stuff, including remind users of their password expiration and force user to change their password if expire didn't work anymore. I can't find any other maybe access right problems within ldap, so why the sambaPwdMustCh...
2003 Jun 20
1
what is the default amount of time that smbpasswd increments the sambaPwdMustChange value
So I get a phone call about my companie's controler not being able to log into samba. About two weeks ago we migrated from Win2k Server to Samba running on LDAP. What would be the default value that sambaPwdMustChange would be incremented? This is NT Time Right (1 unit for every 100 ms from 1600 right?) I just had to bump everybody what I'm guessing is three weeks, but I need to know soon so I don't get woken up out of bed again! -------------- next part -------------- A non-text attachment was scrub...
2004 Sep 29
0
sambaPwdMustChange not properly set with smbldap
I'm using samba 3.0.6 on fedora core 1 with LDAP enabled and smbldap-tools. When I change a user password with smbldap-passwd <username>, i find that sambaPwdMustChange attribute is correctly set to 30 days later as set in smbldap_conf. But, if I try to change password from any Win2000 or WinXP client with CTRL+ALT+CANC --> CHANGE PASSWORD i notice that sambaPwdMustChange attribute is always set to 2147483647. I have tryed different setups in smb.conf but not...
2008 Oct 09
2
sambaPwdLastSet=0 vs sambaPwdMustChange=0
Hi all, Something is unclear to me, maybe someone here can explain. I want to users to get the "you are required to change your password" dialogue, when they logon for the first time. According to the documentation setting sambaPwdMustChange=0 should work. However, on my setup, it does NOT work. The user can log on, but is NOT asked to change his or her password. (docs: http://www.samba.org/samba/docs/man/Samba-HOWTO-Collection/passdb.html#id2586078) Then I tried using "net sam set pwdmustchangenow USERNAME yes" (which is...
2009 Mar 13
1
PAM_WINBIND problem with sambaPwdMustChange
Hi People! I use pam_winbind for authentication in my computer workstation using Debian Lenny 5.0, Stable Version. I configure my user with this option "sambaPwdMustChange: 0", and I logon in GDM without asking to change password. Who knows what can be? I use Samba PDC with Heimdal Kerberos, but, I configure PAM with only pam_winbind for tests... Client versions: ii libwbclient0 2:3.2.5-4 client library for interfacing with winbind...
2011 Jun 20
0
Remove obsolete sambaPwdMustChange and sambaKickoffTime from LDAP database
Dear Samba friends, >From the information I have found on the internet, I understood that sambaPwdMustChange and sambaLogoffTime are obsolete. When there is no use for these attributes in the future, I would recommend to remove them from the samba scheme. What would be the procedure to follow to remove these attributes and to update the ldap database? -- Met vriendelijke groeten, With kind regards, Mit...
2013 Oct 18
0
sambaPwdLastSet and sambaPwdMustChange - major issue
...Separate System) samba-3.6.3-0.18.3 SLES - 10 (For LDAP Backend, Separate System) openldap2-2.3.19-18.7 The above setup is working fine and the password policies are all fine. Problem - If the user changes the password at the Windows Client sambaPwdLastSet changes date to the new date but the sambaPwdMustChange does not change to the next date, ie (sambaPwdLastSet + 90 Days). If the password is set in the command line by the administrator then everything is fine. How do I fix this issue, Please advise. Thanks AVIN
2004 Sep 15
4
Samba3 + smbldap-tools & smbpasswd
...ddling lately with Samba 3 coupled with openldap, nss_ldap, pam_ldap and the smbldap-tools to create a PDC. Following various examples, most things work, but I have an issue with changing passwords from Windows. If I manually change a password with smbldap-passwd, the script correctly adjusts the sambaPwdMustChange attribute according to what defaultMaxPasswordAge is set to. If I change the password through Windows, Samba presumably uses smbpasswd, because the sambaPwdMustChange attribute is then somehow set to only 2 days into the future. The same thing happens if I run smbpasswd manually. As a simple hack...
2007 Aug 13
0
ldap passwd sync on 3.0.25a
...Success (0) My OpenLDAP auditlog file confirms that smbk5pwd is working: # modify 1187006837 o=stars cn=sambamgr,ou=Managers,o=stars dn: uid=lacoste,ou=Users,ou=Accounts,o=stars changetype: modify replace: userPassword userPassword:: e1NTSEF9UFZSZk1zcTNoRlFuYWhGMzRWN1BZWE5BU3U0MHNVTWo= - replace: sambaPwdMustChange sambaPwdMustChange: 1218542837 - replace: sambaPwdLastSet sambaPwdLastSet: 1187006837 - replace: sambaLMPassword sambaLMPassword: 8d16f4badd1da493aad3b435b51404ee - replace: sambaNTPassword sambaNTPassword: b39a61f16a4e11fa80580241f1d4aae8 - replace: pwdChangedTime pwdChangedTime: 20070813120717Z -...
2004 Mar 15
1
smbpasswd trying to add instead of replace attribut
...quot;MOD" from log file (from different domain) : UNSUCESSFULL Mar 15 17:10:53 hurricane slapd[27056]: conn=29489 op=1 MOD dn="uid=pwreka,ou=people,ou=purwakarta,dc=indorama,dc=com" Mar 15 17:10:53 hurricane slapd[27056]: conn=29489 op=1 MOD attr=sambaPwdCanChange sambaPwdCanChange sambaPwdMustChange samb aPwdMustChange sambaLMPassword sambaNTPassword sambaPwdLastSet sambaPwdLastSet Mar 15 17:10:53 hurricane slapd[27056]: Entry (uid=pwreka,ou=people,ou=purwakarta,dc=indorama,dc=com), attribute 'sambaLMPas sword' cannot have multiple values Mar 15 17:10:53 hurricane slapd[27056]: entry f...
2004 Jun 07
2
Password trouble with LDAP (eDirectory)
Hi All, I have a strange problem with passwords, stored in LDAP. When i try to logon as a user with the correct password, access is denied and the log says check_ntlm_password: Authentication for user [administrator] -> [administrator] FAILED with error NT_STATUS_NO_SUCH_USER When i try to logon a user with incorrect password, access is (of course) denied, but the log now says
2003 Dec 11
1
Forcing Users to change passwords.
...; -C 9 # password age 90 days $ pdbedit -P "maximum password age" -C 7776000 Samba takes age in seconds, so 60*60*24*90, is what you need. Remember, that the user has to change his/her password from workstation once, then policy takes effect. Another way is to manually change users "sambaPwdMustChange" value to "0", so user is forced to change password on next logon. After password change, new "sambaPwdMustChange" will be set, with timestamp 90 days forward. $ pdbedit -P "password history" -C 3 Doesn't work. Andrew said, it isn't implemented yet. Samba...
2007 Jul 17
2
[Urgent] Cannot make changes via pdbedit
...If I run pdbedit -Lv -u jrolfe, I get: Password last set: Mon, 01 Jan 2007 03:00:00 EST Password can change: Mon, 08 Jan 2007 03:00:00 EST Password must change: never If I run ../smbldap-usershow jrolfe, I get: sambaPwdCanChange: 1183795200 sambaPwdLastSet: 1167638400 sambaPwdMustChange: 1167638400 The unix times converted to english are: Sat, 07 Jul 2007 08:00:00 GMT and Mon, 01 Jan 2007 08:00:00 GMT. So you can see that the dates do not match between pdbedit and smbldap-tools. This is really causing a problem because I am trying to set up a new user and cannot get his passwo...
2005 Jun 04
3
smbldap-tools and joining workstation to domain
...RG objectClass: top objectClass: posixAccount objectClass: sambaSAMAccount cn: testhost3$ gidNumber: 553 homeDirectory: /dev/null loginShell: /bin/false uid: testhost3$ uidNumber: 1005 sambaPwdLastSet: 0 sambaLogonTime: 0 sambaLogoffTime: 2147483647 sambaKickoffTime: 2147483647 sambaPwdCanChange: 0 sambaPwdMustChange: 2147483647 description: Computer Account rid: 0 primaryGroupID: 0 lmPassword: 7582BF7F733351347D485E46C8E6306E ntPassword: 7582BF7F733351347D485E46C8E6306E acctFlags: [W ] Looking at smbldap-useradd script code I can see that sambaSAMAccount entrys are only added when -i switch is used...
2005 Jun 10
2
samba ldap problem
...root, people, example.com dn: uid=root,ou=people,dc=example,dc=com uid: root sambaSID: S-1-5-21-3527759599-3696857034-3584459987-500 sambaPrimaryGroupSID: S-1-5-21-3527759599-3696857034-3584459987-512 displayName: root sambaAcctFlags: [U ] objectClass: account objectClass: sambaSamAccount sambaPwdMustChange: 2147483647 sambaLMPassword: 63D2114DE42F744B30A84C4AFE5AFFFF sambaNTPassword: 5460FB29D247C383F63E1E3A417FC39B sambaPasswordHistory: 00000000000000000000000000000000000000000000000000000000 00000000 sambaPwdCanChange: 1118395221 sambaPwdLastSet: 1118395221 # win2k$, Computers, example.com dn: ui...
2004 Jul 05
1
Accounts are getting disabled
...lass: person objectClass: organizationalPerson objectClass: top objectClass: sambaSamAccount cn: alexander-cristea sn: alexander-cristea uid: alexander-cristea homeDirectory: /home/kl-1g3/alexander-cristea gecos: "kl-1g3" loginShell: /bin/sh shadowMin: 1 shadowMax: 99999 shadowWarning: 14 sambaPwdMustChange: 1800000000 gidNumber: 112 sambaPrimaryGroupSID: S-1-5-21-3371203057-3264423045-2392767973-1225 uidNumber: 5248 sambaSID: S-1-5-21-3371203057-3264423045-2392767973-11496 sambaProfilePath: \\WILMA2\profile sambaAcctFlags: [UX ] The same user monday morning: # alexander-cristea, kl-1g3, peopl...