Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-1740

Support changing active status (activating/deactivating) for users in ApacheDS directories

    • Icon: Suggestion Suggestion
    • Resolution: Unresolved
    • None
    • Directory - LDAP
    • None
    • java version 1.6.0_16
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      A user account in ApacheDS can't be deactivate when I uncheck "active" and press "Update" button.

          Form Name

            [CWD-1740] Support changing active status (activating/deactivating) for users in ApacheDS directories

            Elian Kool added a comment -

            CWD-2762 has a patch for OpenLDAP which should be easy to adjust for other LDAP schemas.

            Elian Kool added a comment - CWD-2762 has a patch for OpenLDAP which should be easy to adjust for other LDAP schemas.

            I'd like to see this for FreeIPA.

            Brian Topping added a comment - I'd like to see this for FreeIPA.

            You need to leverage the pwdAccountLockedTime attribute for this: It is specified in this draft http://tools.ietf.org/id/draft-behera-ldap-password-policy-10.txt as well as in http://directory.apache.org/apacheds/advanced-ug/4.3-password-policy.html. The draft seemed to be implemented by most of the current LDAP servers, so this would cover OpenLDAP as well.

            Konrad Windszus added a comment - You need to leverage the pwdAccountLockedTime attribute for this: It is specified in this draft http://tools.ietf.org/id/draft-behera-ldap-password-policy-10.txt as well as in http://directory.apache.org/apacheds/advanced-ug/4.3-password-policy.html . The draft seemed to be implemented by most of the current LDAP servers, so this would cover OpenLDAP as well.

            Elian Kool added a comment -

            Actually ApacheDS doesn't have support for the active flag at all. As discussed in CWD-995, it has to be implemented per backend.

            --> Would be great to have support for (a configurable?) LDAP flag to reflect the active/passive state in the LDAP

            Elian

            Elian Kool added a comment - Actually ApacheDS doesn't have support for the active flag at all. As discussed in CWD-995 , it has to be implemented per backend. --> Would be great to have support for (a configurable?) LDAP flag to reflect the active/passive state in the LDAP Elian

              Unassigned Unassigned
              0035a17fadad kcchao
              Votes:
              8 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: