[Freeipa-users] How to change krbPasswordExpiration for service accounts
Sumit Bose
sbose at redhat.com
Tue Jul 2 13:07:33 UTC 2013
On Tue, Jul 02, 2013 at 03:41:54PM +0300, Vitaly wrote:
> I already read
> https://www.redhat.com/archives/freeipa-users/2012-September/msg00026.htmlthread,
> but I am not sure I understand suggested solution.
> So my question - how I can change krbPasswordExpiration for certain account?
>
> ipa user-mod service --setattr=krbPasswordExpiration=20381231011529Z
if you want that the password never expires for some users you should
created a password policy where the password never expires and assign
the policy to the users.
See 'ipa help pwpolicy' for more details.
HTH
bye,
Sumit
>
> returns
>
> ipa: ERROR: Insufficient access: Insufficient 'write' privilege to the
> 'krbPasswordExpiration' attribute of entry
> 'uid=service,cn=users,cn=accounts,dc=example,dc=com'.
>
> TIA,
> Vitaly
> _______________________________________________
> Freeipa-users mailing list
> Freeipa-users at redhat.com
> https://www.redhat.com/mailman/listinfo/freeipa-users
More information about the Freeipa-users
mailing list