[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: [ldapext] Password Policy - locking accounts





John McMeeking wrote:



Is the notion of an administrator locking/unlocking (i.e. enable/disable
for authentication) an entry within the scope of the password policy draft?
This seems like a logical addition and a reasonable candidate for something
to be done in a standard way.

If folks agree, I suggest adding an extended operation to lock or unlock a
given entry.

I don't believe that enabling / disabling an account for authentication is part of the password policy.
I think it is more of a question of a login policy (ie one would like to enable / disable only some part of the day, or during week ends...).
This is outside the scope of the password policy document.




On a related note, it is common to be able to set "password must be reset"
on a per user basis -- for example setting the password for an entry to be
used by an application. This could be done by modifying the pwdReset
attribute, in which I think it would be appropriate for password policy to
specify that servers may allow this attribute to be modified. Or another
extended operation; I don't have any good guidelines for when I think an
extended operation is more appropriate than modifying what has so far been
presented as a "status" attribute -- though I didn't see any
"NO-USER-MODIFICATION" atttached to any of these attributes.


Our implementation allows administrators to modify the operational attributes. It's easier than extended operation and more coupled with Access Controls.
Extended operations are more complex to build in clients and SDKs and Access Controls are to be set for each extended operation as well.


I agree that we should add some text in the draft regarding the possibility to modify some of the attributes.

Ludovic.

John  McMeeking


_______________________________________________
Ldapext mailing list
Ldapext@ietf.org
https://www1.ietf.org/mailman/listinfo/ldapext



-- Ludovic Poitou Sun Microsystems Inc. Sun ONE products - Directory Server Group - Grenoble - France




_______________________________________________ Ldapext mailing list Ldapext@ietf.org https://www1.ietf.org/mailman/listinfo/ldapext