In a thread on Freeipa-devel titled "freeIPA as a samba backend"there is a 
statement as below:
=====
IPA will keep all of your passwords in sync - userPassword, sambaNTPassword, sambaLMPassword, and your kerberos passwords. 389 cannot do this - the functionality that does this is provided by an IPA password plugin. Openldap has a similar plugin, but I
think it is "contrib" and not "officially supported".
======

Can someone please point me to where I can find this plugin and configured it to keep all passwords listed above in sync?
I am unable to find detailed information on password plugin in IPA 2.2 doc.

My intention is to provide my Windows users (accounts on IPA server) IPA web interface only for changing their password.

I am using Samba 3.0.23d as a standalone server because this is a last version that does not check for SIDs strictly...

Many thanks,
Qing

_______________________________________________
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users

Reply via email to