Hi everyone,

We have been using ssp since 8 months and all is great. However, we have to 
comply with some password rules from a major customer.


*        Password complexity : that's ok ssp handles that great

*        Change password after x days : this is where things get tricky, we are 
thinking of

o   using ldap ppolicy extension just to "lockout" the account after X days

o   sending a reminder via email

o   user groans as he is locked out :D

o   ssp then is used as of today to change the password

*        (ideally) password history is challenged (I know I know php-ldap...)



Excluding the password history bullet, is this ok with ssp ?



Password history is next step discussion, I do remember an old thread to 
directly extract the ldap policy info...

Thanks for the help !
Sebastian
_______________________________________________
ltb-users mailing list
[email protected]
https://lists.ltb-project.org/cgi-bin/mailman/listinfo/ltb-users

Reply via email to