Red Hat Bugzilla – Bug 1009829
Document that server side password policies always takes precedence
Last modified: 2014-10-14 00:46:45 EDT
Description of problem: Server side password policies always takes precedence over the policy enabled from client side. e.g. On setting "ldap_pwd_policy=shadow", the policies defined with shadow ldap attributes for a user has no effect if password policy is enabled on the server(openldap). Version-Release number of selected component (if applicable): 1.9.2-127 How reproducible: Always
Upstream ticket: https://fedorahosted.org/sssd/ticket/2091
Fixed upstream: master: 56ed2be9a95cb5713ef72c4933e362a36dc7a607 sssd-1-11: 539fdcebb352722b88a2700f994b1f8b7305b95a
Fixed upstream -> POST
Verified with sssd-1.11.6-1.el6 man sssd-ldap has the following note: Note: if a password policy is configured on server side, it always takes precedence over policy set with this option.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2014-1375.html