Univention Bugzilla – Bug 35013
Make account-lockout-threshold configurable via UMC
Last modified: 2020-07-03 20:54:09 CEST
The account lockout domain setting can only be configured via samba-tool: samba-tool domain passwordsettings set --account-lockout-threshold=2 This setting should be added to UMC (UDM: settings/sambadomain).
It should also be possible to set the attribute "lockoutThreshold" on the domain base.
See also Bug 31907
Wrong Bug number, I meant to refer to Bug 35809.
udm settings/sambadomain has "badLockoutAttempts", which is backed by LDAP attribute sambaLockoutThreshold: udm settings/sambadomain modify \ --dn sambaDomainName=AR41I1,cn=samba,dc=ar41i1,dc=qa \ --set badLockoutAttempts=5 So, the dc.py in univention-s4-connector needs to be extended to also sync the OpenLDAP attribute sambaLockoutThreshold to the AD attribute lockoutThreshold.
Created attachment 9413 [details] s4connector_sync_lockoutThreshold.patch The attached simple patch should fix this. The third parameter in this context requires a little bit more work: * resetCountMinutes / sambaLockoutObservationWindow / lockOutObservationWindow -> UDM syntax is integer, that should be changed to UNIX_TimeInterval, because it's a time interval in Active Directory too
This issue has been filed against UCS 4.2. UCS 4.2 is out of maintenance and many UCS components have changed in later releases. Thus, this issue is now being closed. If this issue still occurs in newer UCS versions, please use "Clone this bug" or reopen it and update the UCS version. In this case please provide detailed information on how this issue is affecting you.