W dniu 12.11.2015 o 13:35, Roderick Johnstone pisze:
I'd like to find a way to disable an account on a date that we can set in the account information. ie like the Account Availability option in Solaris Management Console or the /etc/shadow "account expiration date" concept on Linux.

I couldn't obviously see in the docs or on the list how to do this in freeipa.

Does anyone have any suggestions?

There is " Kerberos principal expiration" field in Web UI (or --principal-expiration option in CLI). When date specified there has passed, it's no longer possible to authenticate using such account.

Best regards,
Mateusz Małek
Manage your subscription for the Freeipa-users mailing list:
Go to http://freeipa.org for more info on the project

Reply via email to