For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Ferg_104721's avatar
Ferg_104721
Icon for Nimbostratus rankNimbostratus
Mar 25, 2013

LDAP Password Expire / Change in APM

Hi

 

I have been searching the forums and KB and have seen many people ask the same question, while AD allows for password alerts on expired password or password needs changed, LDAP does not.

 

Has anyone come across a way round this or even a way to check this attribute and alert the user will next change by their admin or such.

 

I have tried the advanced option under LDAP auth to see if last login under 30 days but got know where.

 

I am a little surprised this is an option for AD alone.

 

Any suggestions appreciated.

 

Thanks

 

 

Ferg

 

2 Replies

  • I have to wonder if the LDAP attributes for account password information are dependent on the system employed. In AD you can use the pwdLastSet and userAccountControl (to see if the account expires at all) values, but I believe that is generally arbitrary in any given LDAP directory. In any case, while you may not be able to change the password with APM, you should certainly be able to query for a value with an LDAP query agent and make a decision based on results (i.e. message box to user indicating impending expiration).
  • Thanks, that what i was thinking as my last resort. Just frustrating APM cant do teh same for LDAP and expired passwords.