[Freeipa-devel] [PATCH] Rewrite pwpolicy plugin based on baseldap.py.

Rob Crittenden rcritten at redhat.com
Fri Jul 31 18:36:36 UTC 2009


Pavel Zůna wrote:
> Fix bugs: 510740, 510739, 510735, 510733, 510532
> 
> Pavel

A couple of issues with the max values. I checked DS and I think the 
maxes should shadow it.

krbpwdhistorylength: 24
krbpwdmindiffchars: 6

And I have some further questions for the team.

Do we want to limit password validity to 1 year max? Do we need a limit 
at all other than maxInt?

Is 30 big enough for a password?

This doesn't seem to enforce that maxlife > minlife.

rob

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3245 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20090731/c91d9320/attachment.bin>


More information about the Freeipa-devel mailing list