14.02.2014 Views

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The shadowLastChange Bug<br />

If a user's object has an objectclass of shadowAccount, upon changing or<br />

setting the password, pam_ldap.so will attempt to update the shadow<br />

attribute shadowLastChange.<br />

The userpasswd attribute is modified via a binding either the DN defined<br />

in /etc/ldap.conf (passwd command executed as the superuser) or as the<br />

user's dn (passwd command executed by the user).<br />

The shadowLastChange attribute should be modified in the context of the<br />

same binding, however, prior to version XXX of pam_ldap.so the P<strong>AM</strong><br />

module would rebind annonymously in order to modify<br />

shadowLastChange. This caused the updating of shadowLastChange to<br />

fail unless anonymous binds were permitted write authortity on the<br />

attribute (a bad idea).<br />

A user does require the ability to modify their own shadowLastChange<br />

attribute in order to provide shadow functionality via pam_ldap.so.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!