Hello,

I am trying to force user to change their password at first logon and on password reset.

        OS                                        RHEL7
        Openldap version         2.4.39-7.el7_1.x86_64


I have tried the following

1)        I have set the pwdMustChange attribute to TRUE in ppolicy,  but when user logon to client at first time or after resetting password, it just allow suer to logon without                 prompting to change the password,

2)        I have set the pwdReset attribute to TRUE in user attribute for particular user, this doesn't allow user to login at all and keep prompting for password without allowing to login.         Also i red in blogs this is not correct way, but couldn't find more information on this.

is there any way to force users to change their password at first logon and after resetting password by admin. ?

Current ppolicy



Thanks & Regards
Raj

=====-----=====-----=====
Notice: The information contained in this e-mail
message and/or attachments to it may contain
confidential or privileged information. If you are
not the intended recipient, any dissemination, use,
review, distribution, printing or copying of the
information contained in this e-mail message
and/or attachments to it are strictly prohibited. If
you have received this communication in error,
please notify us by reply e-mail or telephone and
immediately and permanently delete the message
and any attachments. Thank you