Forum Discussion
Seclab_Supporto
Nimbostratus
Jun 28, 2010Intercept LDAP password expired
Hi all,
I perform LDAP authentication with a custom iRule.
I need to intercept when LDAP password has expired.... and then perform a redirect to an application to reset the password.
Someone can hel...
hoolio
Cirrostratus
Jul 05, 2010As Hamish suggested, it would be good to open a support case to find out what kind of method F5 would recommend.
Hard coding the expire time in an iRule might work if you check if the current time minus the last change time is less than the expiry time. But that would break if the password expiry time was changed on the LDAP server.
I did notice that the attribute Rule ldap:attr:adminCount = 1 is present in the unexpired request and not present in the expired request. If that's always the case, you might be able to use that to detect an expired password.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects