AD & Password Expiration

If you are having a problem using Vault, post a message here.

Moderator: SourceGear

Post Reply
aluetjen
Posts: 40
Joined: Wed May 19, 2004 1:00 am
Location: Germany, Karlsruhe
Contact:

AD & Password Expiration

Post by aluetjen » Fri Jan 07, 2005 10:25 am

Hello!

Scenario:

* Users log on to Vault using their AD accounts
* AD accounts have password expiration and complexity checks set
* However, users have no access to LAN in terms of interactive log on to a machine of the domain.

Problem:

* The user is unable to change his password
* Only workaround through something like OWA or custom Web interface.

Question:

* Can a user change his password out of the Vault Gui? (My first attempts failed, but the Vault feature Change Password is available).
* Does the user receive a "Password will expire soon" warning when logging on to vault?

Best regards, Alex
update4u Software AG

jeremy_sg
Posts: 1821
Joined: Thu Dec 18, 2003 11:39 am
Location: Sourcegear
Contact:

Post by jeremy_sg » Fri Jan 07, 2005 10:39 am

No, Vault can not change the AD password, nor will they get the "password expires soon" message.

aluetjen
Posts: 40
Joined: Wed May 19, 2004 1:00 am
Location: Germany, Karlsruhe
Contact:

Post by aluetjen » Fri Jan 07, 2005 10:52 am

Hmmm, wouldn't it make sense or do you plan enhancement of that? I mean on the one hand you say that AD authentication has been implemented this way because of users use vault without being logged on to the domain (otherwise using the existing credentials is the only reasonable way). On the other hand major features given by AD cannot be really used as the log on mechanism is a little too proprietary.

I'm asking again because implementing the change password would be something like a "<100 lines of code" thing ;)
update4u Software AG

jeremy_sg
Posts: 1821
Joined: Thu Dec 18, 2003 11:39 am
Location: Sourcegear
Contact:

Post by jeremy_sg » Fri Jan 07, 2005 3:14 pm

My feeling is that most administrators wouldn't like the idea of Vault being capable of changing a domain user's password. But you're right in that we should probably disable the change password option for active directory users and pass on the "password expires soon" message.

Post Reply