vavavr00m / pwm

Automatically exported from code.google.com/p/pwm
0 stars 0 forks source link

Unable to change user password if Min Password age 1 or greater #254

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
What steps will reproduce the problem?
1.  In your GPO set the Min Password age from "Not Defined" to 1

2.  Run GPUPDATE /FORCE

3.  Login to PWM or SSPR and try to change user password in SSPR / PWM and you 
go back to change password page with no error.

4.  You can set Min Password age to "0" however then this goes against AD 
Security policies and a user could change their password all day and cycle 
through the passwords remembered to get back to that and use same password over 
and over.  This is a road block to prevent that however if it was 4 remembered 
they could change every day then one 5th day go back to default.

What is the expected output? 
Some error other than going back to change password page.  At this time you 
must be an admin and look at the log file to see this error.

What do you see instead?
Change Password page and no message of error so user could be in a loop.

What version of PWM are you using?
1.62

What ldap directory and version are you using?
AD

Please paste any error log messages below:

4006 PASSWORD_BADPASSWORD (error setting password for user 'CN=Camden 
Messenger,CN=Users,DC=ad,DC=utopia,DC=netiq,DC=com'' [LDAP: error code 19 - 
0000052D: AtrErr: DSID-03190F80, #1:
    0: 0000052D: DSID-03190F80, problem 1005 (CONSTRAINT_ATT_TYPE), data 0, Att 9005a (unicodePwd)
])

Original issue reported on code.google.com by KP.RedWi...@gmail.com on 3 Aug 2012 at 5:33

GoogleCodeExporter commented 9 years ago
Latest PWM builds will now work with AD configured in this way.

Original comment by jrivard on 4 Feb 2013 at 3:08