[Freeipa-users] Restrict AD users from passwd

Simo Sorce simo at redhat.com
Wed Aug 14 14:32:01 UTC 2013


On Wed, 2013-08-14 at 09:48 -0400, Brian Lee wrote:
> Hi Sumit,
> 
> 
> Thanks for the suggestion. I'll have to give this some thought, since
> we have 100+ AD servers, this might not be well received by the AD
> team. If anyone can think of a better mousetrap than this, let me
> know.

Do you also block the 'net user' command on Windows clients ?
It's the same as 'passwd' on Linux clients.

I would address the problem by using proper password policies as I (now)
see Petr recommended i another email.

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York




More information about the Freeipa-users mailing list