Forum Discussion
APM iRule to "replicate" password change between AD and stand-alone servers
Hi Nikolay,
If I where you, then I would turn the DB accounts into shadow accounts.
I would change the passwords of the DB to a value which is unknown to end users, but known by your APM (using datagroups or by using a strong and fixed password for every DB user). Then inject those DB credentials during APM logon into the session and use them whenever the user requests content from the application servers.
AD Account => APM Session => DB Account
By doing this the users would still login to your F5 using your AD credentials and every application. And they could change the AD password as usual and as often they want. But without the need for manual or automatic password replication...
Cheers, Kai
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
