Hi, all

According to the integration document, after extend the schema on Microsoft
Active Directory server, one of the advantage is that it allows to change
password on AD server. One of our client did extend the schema on their test
AD server but the user is not able to change their password on their laptop
when they login.
The test is conducted as this:

1. extend the schema on test AD server, create a test user id who is not on
production AD server to avoid conflict.
2. remote user login to the firewall (NG AI R55) using test user id, login
succeed.
3. change the test user's attribute, i.e. for the user enable "change
password at next login" property on test AD server.
4. remote test user can't login anymore with the message "wrong user name or
password".
5. disable the property "change password at next login" on test AD server.
6. remote test user can login again no problem.

Has anyone successfully implemented extend schema on AD server and remote
user can change their password when they login and their password expired?
Thanks in advance.


Ryan

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to