04.06.2013 Views

UCS 2.4 - Univention

UCS 2.4 - Univention

UCS 2.4 - Univention

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4 <strong>Univention</strong> Directory Manager<br />

56<br />

The following interconnections between the different login methods are derived from the <strong>UCS</strong> PAM<br />

configuration:<br />

• The Linux login (e.g., on GDM or a tty) is only deactivated if all login methods are deactivated;<br />

a deactivated POSIX account alone is not enough.<br />

• Samba requires a not-deactivated POSIX account - that means that the deactivation of the<br />

POSIX account automatically deactivates Samba as well.<br />

• The Kerberos library (Heimdal) also evaluates the Samba account settings - that means that<br />

the deactivation of the Windows account will also deactivate Kerberos.<br />

Change password on next login<br />

If this checkbox is ticked, then the user has to change his password during the next login procedure.<br />

If the option is activated, the present date will be used as the expiry date for the current password.<br />

Further details can be found in the description Expiry Date on the same tab.<br />

Locked login methods<br />

This selection field can be used to block individual login methods. This can happen automatically<br />

for security reasons, for example, if a user has entered his password incorrectly too often. Normally<br />

users should always be blocked for all login methods.<br />

In contrast to Account deactivation, the account is not blocked, but the login is denied. The following<br />

login methods can be restricted:<br />

• None<br />

• Locked all login methods<br />

• Locked Windows/Kerberos only<br />

• Locked POSIX/LDAP only<br />

’Mail’ tab<br />

Primary e-mail address<br />

The primary e-mail address of the user is declared here. E-mail addresses can consist of the following<br />

characters: letters a-z, numerals 0-9, dots, hyphens, and underlines. The address has to begin with<br />

a letter and must include an @ character.<br />

Alternative e-mail addresses<br />

Further e-mail addresses can be declared here for the user. E-mails to these addresses will be<br />

delivered to the same inbox as mails sent to the user’s primary e-mail address. It is possible for<br />

several users to use the same alternative e-mail address. However the multi-used alternative e-mail<br />

address should not be used as the primary e-mail address by one of the users.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!