On Tue, Nov 19, 2024 at 12:30:27PM +0000, Windl, Ulrich wrote:
Hi!
Me again after 10 years with basically the same question (https://www.openldap.org/lists/openldap-technical/201411/msg00044.html): What is the meaning of messages like these (note the number of messages created):
Nov 19 11:53:47 v07 slapd[2606]: ppolicy_bind: Setting warning for password expiry for uid=user = 1040879 seconds ...
So the server logs such an entry every few seconds. I might guess that the user tried to authenticate every few seconds (for whatever reason).
If you set your log level to trace, you will get logs that document decisions made during the tool/server operation. As a user, that is what I want out of a level with a name like that.
But what I wonder most: The LDAP server does not seed to "set" the password expiration; it just has to check the value. And for the latter I see no need to log it in syslog.
They are probably "set" on the response control?
It seems the number is the number of seconds until the password actually expired.
So is that a (historic) bug?
Not sure what makes you think this is even a bug?
Regards,