Description of problem: PassSync does a ldapmodify on the userPassword attribute on FDS. So an optional password change plugin on FDS, like ipa-pwd-extop, never gets triggered Actual results: Only the userPassword attribute is changed on FDS Expected results: UserPassword, samba hashes and krbPrincipalKey should get modified when using a password change plugin like ipa-pwd-extop Additional info:
This falls under the category of RFC correctness
Upstream ticket: https://fedorahosted.org/389/ticket/122
Closing this bug since we moved to the ticket system: https://fedorahosted.org/389/ticket/122