[Freeipa-users] Mountain Lion GUI Login (Expired passwords / Mavericks too)

Jason Woods devel at jasonwoods.me.uk
Thu Mar 13 18:32:08 UTC 2014


Hi

>> 
>> I don't have OS X, but every time I create a new test user on linux and log
>> in to test it, I get bit by the fact that the passwd change always asks for
>> the existing password first, before asking for the new password. So I have
>> to enter the original password once to login, once to make passwd happy,
>> and then enter the new password. Are you sure the dialog box isn't asking
>> for the existing password first?
>> 
>> 
>> Robert
>> 
>> --
>> Senior Software Engineer @ Parsons
>> _______________________________________________
>> Freeipa-users mailing list
>> Freeipa-users at redhat.com
>> https://www.redhat.com/mailman/listinfo/freeipa-users
> Well I still haven’t had any responses since that time.
> 
> I wish we could resolve this since it’s the only little bit remaining to have a full FreeIPA integration.
> 

Yeh it's the only thing wrong for me.

To answer Robert's question though - the reset password is a pop up with an arrow to the login and the original password is still there - so I would assume so. Guessing this is gonna need deeper investigation though but I suspect it's more on the Apple side :-(

> BTW we also integrated sudo-ldap on our OSX machines. The only thing is that you have to upgrade the sudo packages with this one.
> 
> sudo-1.8.9p3.pkg
> 
> and then:
> 
> installer -pkg /prod/sysadmin/darwin/software/sudo/sudo-1.8.9p3.pkg -target /
> mv /usr/bin/sudo /usr/bin/sudo.orig
> ln -s /usr/local/bin/sudo /usr/bin
> 
> then you modify sudo-ldap and nsswitch.conf same thing as on the linux boxes.
> 
> 
> 
> 
> -- 
> 
> 
> Davis Goodman
> Directeur Informatique  |  IT Manager
> <logo_dd_small.png>
> 5605 Avenue de Gaspé, Suite 408  |  Montréal, QC H2T 2A4 
> Tél: +1 (514) 360-3253 x104            Cell: +1 (514) 994-7360 
> 

Thanks for that! We've not got around to any sudo and not really needed but it's great to know it's certainly possible and fairly straightforward!

Jason
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20140313/460ec6f6/attachment.htm>


More information about the Freeipa-users mailing list