[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: ppolicy woes

Robert Evans wrote:
If I include the ACL access part in the slapd.conf file (shown below),
I can't ssh into a client that is using the server to authenticate.
If I remove the access section, I can connect just fine, but then it
authenticates me even though an ldapsearch with the -e ppolicy flag
shows "ldap_bind: Invalid credentials (49); Account locked"

Haven't really checked if your configuration is valid, but I assume it is. I have had problems getting anything to properly obey ppolicy (so with most things you probably have to adapt it by hand). The closest thing to obeying it was ssh, but even then it seemed to be a hit and miss affair.

If you use pam, did you add "pam_lookup_policy yes" anywhere?