freeipa/daemons/ipa-slapi-plugins/ipa-lockout/lockout-conf.ldif
Rob Crittenden cf9ec1c427 Update kerberos password policy values on LDAP binds.
On a failed bind this will update krbLoginFailedCount and krbLastFailedAuth
and will potentially fail the bind altogether.

On a successful bind it will zero krbLoginFailedCount and set
krbLastSuccessfulAuth.

This will also enforce locked-out accounts.

See http://k5wiki.kerberos.org/wiki/Projects/Lockout for details on
kerberos lockout.

ticket 343
2011-01-21 13:59:24 -05:00

16 lines
461 B
Plaintext

dn: cn=IPA Lockout,cn=plugins,cn=config
changetype: add
objectclass: top
objectclass: nsSlapdPlugin
objectclass: extensibleObject
cn: IPA Lockout
nsslapd-pluginpath: libipa_lockout
nsslapd-plugininitfunc: ipalockout_init
nsslapd-plugintype: object
nsslapd-pluginenabled: on
nsslapd-pluginid: ipalockout_version
nsslapd-pluginversion: 1.0
nsslapd-pluginvendor: Red Hat, Inc.
nsslapd-plugindescription: IPA Lockout plugin
nsslapd-plugin-depends-on-type: database