On 12/19/2013 10:24 PM, Simo Sorce wrote:
I have been looking at how we deal with krbpwdpolicypreference as we
found issues with AD synced users, which get no password policy :/

I found out that we do not rely on CoS anymore for setting the attribute
(origin of this bug I would guess), but instead explicitly set the
policy on user objects.

Why is that ?

Also I still see in bootstrap-template.ldif that we create a Password
Policy object in cn=accounts in theory, but I do not have this object on
my server, what happens to it, what removes it ? Why ?

I don't see it in any update file. Was your server installed before this was added (2009-10-02)?

--
PetrĀ³

_______________________________________________
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel

Reply via email to