Bug 52929 - (Member)Server will locked out during server password change
(Member)Server will locked out during server password change
Status: NEW
Product: UCS
Classification: Unclassified
Component: LDAP
UCS 4.4
Other Linux
: P5 normal (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-03-16 20:53 CET by Dirk Schnick
Modified: 2021-03-16 20:53 CET (History)
0 users

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 3: Simply Wrong: The implementation doesn't match the docu
Who will be affected by this bug?: 2: Will only affect a few installed domains
How will those affected feel about the bug?: 2: A Pain – users won’t like this once they notice it
User Pain: 0.069
Enterprise Customer affected?: Yes
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number: 2021020921000697
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Dirk Schnick univentionstaff 2021-03-16 20:53:48 CET
In a customer environment we have seen, that memberservers are locked out during the server password change. In the environment ppolicy and faillog is activated. The servers are used as samba share servers. During the password change a service (probably samba) tries to authenticate with the old password and causes a lockout of the servers machine account. If necessary I can provide logs f.e. directory logger; but I think it is not.

There are two possible ways to fix in my mind.

Stop services at the beginning of server password change (probably causes other unwanted circumstances)

Create the possibility to exclude (machine) accounts from the lockout. Via UCRV would be terrific.