Bug 1009829

Summary: Document that server side password policies always takes precedence
Product: Red Hat Enterprise Linux 6 Reporter: Kaushik Banerjee <kbanerje>
Component: sssdAssignee: Jakub Hrozek <jhrozek>
Status: CLOSED ERRATA QA Contact: Kaushik Banerjee <kbanerje>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 6.5CC: dpal, grajaiya, jgalipea, lslebodn, mkosek, pbrezina
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: sssd-1.11.5.1-1.el6 Doc Type: Bug Fix
Doc Text:
Do not document
Story Points: ---
Clone Of:
: 1009922 1087699 1088106 (view as bug list) Environment:
Last Closed: 2014-10-14 04:46:45 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1009922, 1061410, 1087699, 1088106    

Description Kaushik Banerjee 2013-09-19 09:06:59 UTC
Description of problem:
Server side password policies always takes precedence over the policy enabled from client side.

e.g. On setting "ldap_pwd_policy=shadow", the policies defined with
shadow ldap attributes for a user has no effect if password policy
is enabled on the server(openldap).

Version-Release number of selected component (if applicable):
1.9.2-127

How reproducible:
Always

Comment 2 Jakub Hrozek 2013-09-19 10:54:59 UTC
Upstream ticket:
https://fedorahosted.org/sssd/ticket/2091

Comment 3 Jakub Hrozek 2013-09-24 13:11:43 UTC
Fixed upstream:

    master: 56ed2be9a95cb5713ef72c4933e362a36dc7a607
    sssd-1-11: 539fdcebb352722b88a2700f994b1f8b7305b95a

Comment 4 Jakub Hrozek 2013-09-25 23:03:09 UTC
Fixed upstream -> POST

Comment 7 Kaushik Banerjee 2014-07-07 05:45:02 UTC
Verified with sssd-1.11.6-1.el6

man sssd-ldap has the following note:

 Note: if a password policy is configured on server side, it always takes precedence over policy set with this option.

Comment 8 errata-xmlrpc 2014-10-14 04:46:45 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2014-1375.html