Home Forums OS X Server and Client Discussion Open Directory Per-user or per-group password policy in OD?

Viewing 4 posts - 1 through 4 (of 4 total)
  • Author
    Posts
  • #365918
    zamoose
    Participant

    Howdy all:
    I’ve been scratching my head over this one – it seems as if there’s an ability in Open Directory to set password policy, but it sets it globally. I want to maintain two separate password policies – one for Joe Sixpack User and one for a group of admins (the admins need to have a shorter password expiration window and must have stronger password checking enforced).

    Is there any simple way to do this in OD? I can’t find anything in WGM that would be applicable and I’m heartily hoping I don’t have to edit the LDAP entries by hand.

    Thanks.

    #365919
    Anonymous
    Participant

    policies are not currently applied to admin users at all in 10.4.

    #365920
    zamoose
    Participant

    Perhaps I didn’t explain myself well enough – these are not uid-0-equivalent “admins” rather, they gain their admin status (currently) via sudo (policy set to `ALL: ALL` to allow for this). From OD’s perspective, they should appear as normal users. sudo will take care of the rest.

    #365965
    zamoose
    Participant

    Anyone? Bueller? Ideas, thoughts, comments?

Viewing 4 posts - 1 through 4 (of 4 total)
  • You must be logged in to reply to this topic.

Comments are closed