https://bugs.openldap.org/show_bug.cgi?id=9813
Issue ID: 9813 Summary: Incompatibility between remoteauth and ppolicy overlays Product: OpenLDAP Version: unspecified Hardware: All OS: All Status: UNCONFIRMED Keywords: needs_review Severity: normal Priority: --- Component: overlays Assignee: bugs@openldap.org Reporter: thierry.pubellier@paris.fr Target Milestone: ---
Hi,
We are planning to use OpenLDAP as a proxy for some users in our Active Directory servers, using remoteauth overlay.
We want this OpenLDAP instance to also implement an account lockout policy, preventing the lockout on our internal Active Directory servers.
But there seems to be an incompatibility between remoteauth and ppolicy overlays : remoteauth won't remote authenticate a user if local userPassword attribute exists, while ppolicy overlay needs this attribute.
Could there be a configuration parameter in ppolicy to allow lockout checks/modifications (which seemed to be the default behavior of OpenLDAP before ITS#7089) ?
I can provide a patch if allowed.
Thanks by advance,
Best regards,
Thierry