<div dir="ltr"><pre class="">We currently have 18 master ODSEE servers that we use to provide authentication services to both Redhat, SuSE, and Solaris systems. We are looking to add IPA servers to
<span style="font-size:10pt;font-family:"Courier New"">environment. </span></pre>
<pre class=""></pre><pre class="">We have a requirement to track time of last authentication. With ODSEE, time of last authentication tracking is enabled with this:
</pre><p style="margin:0in 0in 0.0001pt"><b><span style="font-size:11pt;font-family:"Calibri","sans-serif"">dsconf set-server-prop
pwd-keep-last-auth-time-enabled:on</span></b></p>
<br><pre class="">Looking at the Redhat DS 9 documentation, I see an account policy plug-in: <br></pre><pre class=""><br>cn=Account Policy Plugin,cn=plugins,cn=config<br><br></pre><pre class="">Looking the <a href="http://freeipa.org">freeipa.org</a> pages on the server plugins, I do not see the account policy plugin listed.<br><a href="http://www.freeipa.org/page/Directory_Server">http://www.freeipa.org/page/Directory_Server</a><br><br></pre><pre class="">Looking in the directory DT of a "VERSION: 4.2.0, API_VERSION: 2.156" installed on Redhat 7, I do see the account policy plugin in the config tree.<br><br><br></pre><pre class="">Is the use of this account policy plugin supported with IPA? Should it work?<br><br></pre><pre class="">Thanks,<br><br></pre><pre class="">Bob Harvey<br></pre><pre class=""><br></pre></div>