Hi

On Thu, Dec 8, 2011 at 11:09 PM, Rich Megginson <[email protected]> wrote:

> On 12/08/2011 09:36 AM, Iain Morgan wrote:
> > Hello,
> >
> > Is there any way to have 389 DS automatically update the
> > shadowLastChange attribute when the userPassword attribute is changed
> > for an entry?
> No.
> > I know that pam_ldap will attempt to update the shadowLastChange
> > attribute, but this either requires that the user has the privileges to
> > update this attribute. What I would like is for the server to update the
> > attribute directly without having to grant extra privileges to the user.
> >
> > Is there any way to do this?
> >
> > Thanks
> >
>
> --
> 389 users mailing list
> [email protected]
> https://admin.fedoraproject.org/mailman/listinfo/389-users
>

This has nothing to do with 389 Directory Server. It should be included in
LDAP client programs which are used to authenticated & give password change
feature against LDAP Server

This functionality is recently added in NSLCD nss-pam-ldapd
http://lists.arthurdejong.org/nss-pam-ldapd-commits/2010/msg00302.html

RFE to add above in SSSD is in process. Refer
https://bugzilla.redhat.com/show_bug.cgi?id=739312

-- 
Arpit Tolani
--
389 users mailing list
[email protected]
https://admin.fedoraproject.org/mailman/listinfo/389-users

Reply via email to