[Fedora-directory-users] Previous password still works?

Chris Halstead chris at sourcelabs.com
Thu Apr 26 17:28:32 UTC 2007


Hi folks,

I've been googling 'til my eyes bleed but I can't find anything on this.

We're using FDS 1.0.2 and I recently used the admin console (logged in 
as myself, not as the admin account) to change my personal account 
password.  The new password worked, so far so good.  The problem is that 
my *old* password still worked as well.  Everywhere.  Login through PAM, 
login to the FDS admin console, you name it.

After doing some testing I've found that if I change my password logged 
in as myself the old password will still work, yet if I change it logged 
in with our admin user account only the new one works.  What am I missing?

I was planning on putting together a web-form for user password changes 
(using the user's credentials to bind), but if user password changes 
won't invalidate old passwords I'm going to have to change my approach.

-chris




More information about the Fedora-directory-users mailing list