UAL_PASSWORD_AGED=IGNORE/WARN/ERROR Question/Issue

Discuss the Scalix Server software

Moderators: ScalixSupport, admin

Jakes
Posts: 45
Joined: Tue May 15, 2007 8:11 am
Location: Johannesburg, South Africa

UAL_PASSWORD_AGED=IGNORE/WARN/ERROR Question/Issue

Postby Jakes » Fri Jan 07, 2011 5:49 am

Hello all.

I would like to enforce password policies on a server that previously did not have any enforcement. The issue that I am having is as soon as I apply the password expire in X number of days all the users are immediately requested to change their password at next login as most of them have not changed their passwords in over a year. I would prefer for them to get a couple of day’s notification that their password has expired or will expire soon and they need to change it. I tested UAL_PWD_WARNING_DAYS=XX in general.cfg and it worked correctly but UAL_PASSWORD_AGED=IGNORE/WARN/ERROR does not seem to work as expected. I get the expected behaviour from setting IGNORE or ERROR but when set to WARN the user is still asked to change their password and not allowed to access their mail box. Does anybody have any ideas on what is wrong or do I not understand the Administration Guide correctly?

UAL_PASSWORD_AGED=
IGNORE, WARN, or ERROR

This option determines the effect of an expired password on a user logging in to
Scalix through a client.
The default value is ERROR. If the user’s password has expired, an error is generated
when the user attempts to log in and the login fails. The login can only
succeed when a valid new password is supplied.
If the value is set to WARN and the user’s password has expired, the user can
log in using the expired password but a warning message is placed in their Inbox
stating that their password has expired and needs to be changed immediately.
(This message appears in the Inbox for the first login of the day.)
If the value is set to IGNORE, any user password expiration condition is
ignored, and a Scalix user is allowed to log in even though their password has
expired.


Regards
Jakes

mikethebike
Posts: 566
Joined: Mon Nov 28, 2005 4:16 pm
Location: England

Re: UAL_PASSWORD_AGED=IGNORE/WARN/ERROR Question/Issue

Postby mikethebike » Mon Jan 10, 2011 10:23 am

Jakes,

a solution would be to reset your password, then check in the userlist for the attribute that shows the last password change (I cannot remember the attr name, and do not have access to a scalix system).

omsearch -e userlist -t h -e s=smith/g=jake

Then you can use that to apply that last changed date to all users using ommodent.

Make sure you make a backup of the userlist first, and be VERY careful. Its not a great idea to mess with the userlist, but fine if you know what you are doing.

Mick

Jakes
Posts: 45
Joined: Tue May 15, 2007 8:11 am
Location: Johannesburg, South Africa

Re: UAL_PASSWORD_AGED=IGNORE/WARN/ERROR Question/Issue

Postby Jakes » Wed Jan 12, 2011 10:26 am

Thanks Mick.

That’s sounds like a great solution, I will try it on my test server and see how it goes.

Jakes


Return to “Scalix Server”



Who is online

Users browsing this forum: No registered users and 5 guests