Aram Akhavan via FreeIPA-users wrote: > As documented in https://www.freeipa.org/page/New_Passwords_Expired I can see > that when an admin creates a new user or resets a password, it is immediately > expired. Users can log in and immediately change it. However, I'm unable to > get that to work whether from the web gui, ssh, or anything else. > > I've created a test user with admin privileges; it's password is expired. I > try logging into the web UI, and it says "The password or username you > entered is incorrect", nothing about an expired password (I know the password > is right!). The response header of the GUI POST request has > X-IPA-Rejection-Reason: invalid-password, not X-IPA-Rejection-Reason: > password-expired as is suggested here: > https://github.com/freeipa/freeipa-webui/discussions/29 > > If I log in to the ipa server with my own user account (which somehow, I > managed to create and use without issue...), and try to do an `su test`, I > see krb5_child complain: Password has expired. > > It seems impossible to log in with an expired password. Yet my own user > account was created, so presumably I changed some setting but I can't for the > life of me figure out what I changed.
Look at the user entry to see if they have the ipaNTSecurityIdentifier attribute. If not then that's the likely reason. rob -- _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
