mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2026-08-14 06:54:55 -05:00
Disable password schema update on LDAP bind
389-DS 1.4.1+ attempts to update passwords to new schema on LDAP bind. IPA blocks hashed password updates and requires password changes to go through proper APIs. This option disables password hashing schema updates on bind. See: https://pagure.io/freeipa/issue/8315 See: https://bugzilla.redhat.com/show_bug.cgi?id=1833266 See: https://pagure.io/389-ds-base/issue/49421 Signed-off-by: Christian Heimes <cheimes@redhat.com> Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
This commit is contained in:
@@ -66,3 +66,10 @@ only:nsslapd-allow-hashed-passwords:on
|
||||
# Decrease default value for IO blocking to prevent server unresponsiveness
|
||||
dn: cn=config
|
||||
only:nsslapd-ioblocktimeout:10000
|
||||
|
||||
# 389-DS 1.4.1.6+ attempts to update passwords to new schema on LDAP bind.
|
||||
# IPa blocks hashed password updates and requires password changes to go
|
||||
# through proper APIs. This option disables password hashing schema updates
|
||||
# on LDAP bind, see https://pagure.io/freeipa/issue/8315
|
||||
dn: cn=config
|
||||
only: nsslapd-enable-upgrade-hash:off
|
||||
|
||||
Reference in New Issue
Block a user