[Freeipa-devel] account inactivation

Simo Sorce ssorce at redhat.com
Tue Nov 6 22:55:49 UTC 2007


On Tue, 2007-11-06 at 17:41 -0500, Rob Crittenden wrote:
> Ok, I'm working on the "deactivate a whole group" thing.
> 
> I managed to get it working and inactivated a group. I can still get a 
> ticket with those members but binding to LDAP returns:

I was looking into account inactivation on the flight, but the problem
with kldap is that I couldn't find any attribute to do that (although I
was sleepy I admit).
I suspect there may be something in the data blob kldap sticks into ldap
(bleah).

> Account inactivated. Contact system administrator.
> 
> Cool.
> 
> Now how do I re-activate them? I deleted the nsAccountLock attribute but 
> I still cannot connect to FDS.

Are you getting refused even after doing a new bind ?

Simo.




More information about the Freeipa-devel mailing list