Password policy "be changed at next login" stopped working

Due to a system failure of a 10.8.5 Open Directory master, I migrated it to a new 10.10.1. Migration seemed flawless, but now I'm experiencing a weird failure of the password policy "be changed at next login". It's simply ignored.
10.8.5 description:
- virtual machine with VMWare ESxi 5.5u1, 8 GB RAM, 60 GB hard drive plus a second one 150 GB
- Server version 2.2.2, Workgroup Manager version 10.8 (409)
- Open Directory with a self generated certificate for SSO
- all the users have mobile account with local home template
10.10.1 description:
- virtual machine with VMWare ESxi 5.5u1, 8 GB RAM, 80 GB hard drive plus a second one 120 GB
- Server version 4.0.3 (14S350), Workgroup Manager 10.9 (421)
Migration procedure: installed ex-novo 10.10.1, at the end of installation migrated data through migration assistant from old server hard drive attached at the new VM, switched off VM, detached old server hardware, rebooted, downloaded and installed new Server version.
All the computers bound to the Open Directory master allowed login so I thought the migration went properly, untile I discovered that the policy to change the password at next login doesn't work anymore.
Anyone having hints/suggestions about this behaviour?
Thanks
               Luca

Thank you for the suggestion. I cleared the policy database with the command you sent, but in workgroup manager I still find "be changed at next login" checked. If I check the password policy of my test user 98765 this is what I find:
server:~ root# pwpolicy -u 98765 -getpolicy
Getting policy for 98765
hardExpirationDate=1970-01-01 00:00:00 +0000 requiresAlpha=0 maxMinutesOfNonUse=0 usingHistory=0 maxFailedLoginAttempts=0 newPasswordRequired=1 expirationDate=1970-01-01 00:00:00 +0000 usingHardExpirationDate=0 maxChars=0 usingExpirationDate=0 maxMinutesUntilChangePassword=0 minChars=0 canModifyPasswordforSelf=1 requiresNumeric=0
newPasswordRequired is correctly set at 1, but there is no prompt to change password when I try to login. I don't if it's correct, but if I check the password policy after I logged on a computer, I find nothing:
staff:~ root# pwpolicy -u 98765 -getpolicy
Getting policy for 98765
staff:~ root#
Is this correct? Is the policy transferred to the login computer and in this case the transfer fails for some reason?
Thanks for the help
               Luca

Similar Messages

  • Jabber for Windows Login failed with - "Must change at Next Login" for CUCM Authentication

    Jabber for Windows users cannot login when "User Must Change at Next Login" is selected in the CUCM credential Policy
    I found this Bug-ID: CSCuh84476
    https://tools.cisco.com/bugsearch/bug/CSCuh84476
    We use Jabber for Windows 9.7.4!
    I just want to know if there are other users have the same problem and which workaround they applied.
    I’m currently testing a User with different Policy credentials (Credentials expire after 1 day).
    I think this will also lead to a “username or password wrong”-popup but tomorrow I will see it myself ;)
    The planed workaround for us will be to set the “User Must Change at Next Login ” option and the users first have to login at UCM-Userpage to change their initial password.
    BTW: Maybe somebody from Cisco know when this get fixed?
    Best regards
    Franz

    J4W does rely very heavily on DNS, you should at least all required entries to hosts and lmhosts.
    How are your servers defined under system -> server??
    Are you able to log into UCMuser page??
    Have you properly configured all user/device/line association, and created the necessary service profiles???

  • Changed password on Creative Cloud account - will apps stop working?

    Hi,
    My laptop with Creative Cloud CS6 installed was stolen in a burglary at our house. Fortunately I didn't lose much as I had recently done a clean install (to install CS6!)
    I have changed my password on all my accounts, including Creative Cloud. Does this mean that
    1) The apps installed will not longer work as they cannot get a license
    2) When I get a replacement laptop I will be able to activate Creative Cloud on that laptop
    I am concerned because, while my insurance is replacing hardware, it doesn't cover software.
    Thanks,
    Chris.

    Many thanks for the reply.
    Will the apps stop working after 30days when they prompt to be re-authenticated? Does authentication require someone to know the Adobe ID and password?
    Thanks,
    Chris.

  • I can no longer edit song and album information in iTunes. I right click on the album, the window opens with "get info", "rating", etc., but none of it operates. What did I change to make it stop working?

    I can no longer edit album or song information in iTunes. I right-click on the album (or song), and the window opens with "get info", "rating", etc., but none of it operates. It won't get or save album art, anything. What have I changed to make it all stop working?

    You are describing an iTunes problem, not an iPod touch problem. Try posing in the iTunes forum.

  • Network logins stop working

    Greetings,
    Our school has a number of 10.4.7 eMacs that are bound to our OD server (10.3.9 X Server: can't upgrade to 10.4.8 server yet). Clients have static IP addresses and use the X Server as it's primary DNS. Forward and reverse lookups work great. Clients are bound to the server through Directory Access settings that we set manually. Users can login and get automount homes. Using 'dscl localhost' at command line and browsing LDAP shows the mappings to users on the OD server are working. Here is the issue. Periodically a user will logout and another user will go to login and the login window will 'shake its head'. The behavior is both sporadic and random. Generally a restart will solve this but one time I had to recreate a user account to get it working for that user again. We can't seem to find a pattern that will suggest why this is happening. Console logs have not offered hints. Anyone seen this and have any ideas?
    Thank you.
    OS X Server and Client   Mac OS X (10.4.7)   10.3.9 OD server
    OS X Server and Client   Mac OS X (10.4.6)  
    OS X Server and Client   Mac OS X (10.4.6)  

    If you have a leased line... I'd submit a ticket and have them do a network diagnostic, not you. But sounds like it is just you, so not a widespread event.
    Sometimes the best or only way is to swap parts. AccelerateYourMac has Mac compatible enet cards and wireless 3rd party or how to replace / install yourself. Add wireless card from Apple or 3rd party.
    Even swapping out cables.
    APC will warrant equipment IF any and all sources of surge etc are protected. You might give AppleCare and tell them your ethernet stopped working, and they might want to look at it or do something, and have better tests. A network surge protector from APC has RJ11/RJ456/coax filters.
    Or maybe someone here knows or in your company how to use a meter to see what is happening.
    http://www.xlr8yourmac.com/osx/osx_networkcards.html

  • Subportal doesn't change when the user's group is changed, until next login

    Hi,
    We have two subportals: Physician and Resident. We also have two groups: Physicians and Residents. Users belonging to Physicians see the Physician subportal when they login, and Residents see the Resident suportal. When a Resident becomes a Physician, we move the user from the Resident group to the Physician group (programmatically) when they log in for the first time after this event. Unfortunately, the resident still gets logged in to the Resident subportal. However the next time they log in, they are sent to the Physician subportal. So we are logging out the user when this happens. Can anyone suggest how the user can be redirected to the correct subportal after a group change? Could this be some kind of caching issue? Maybe there is a way to log the user in a second time behind the scenes?
    We are using Plumtree version 5.5
    Appreciate your help.
    Regards,
    R.A.
    Edited by: user2334044 on Jul 30, 2009 11:24 AM

    In reply to my own post, what we ended up doing eventually was a behind the scenes log out and log back in. Unfortunately we had to store the password in session, which is not a good practice.
    Here is what we did:
         private AActivitySpace m_asOwner;
         public void Init(IModel model, AActivitySpace space)     {
              m_asOwner     = space;
         public Redirect CheckActionSecurityAndExecute(XPHashtable arguments)     {
              IXPRequest iXPRequest = m_asOwner.GetCurrentHTTPRequest();
              XPSession xPSession = iXPRequest.GetSession();
              String usersPassword = (String)xPSession.GetAttribute("usersPassword"); // this was added to the session in OMDGuestLoginActions
              Redirect redirect = new Redirect();
              redirect.SetLinkCreateNewSpace(LoginAS.STR_MVC_CLASS_NAME, null);
              redirect.AddControlArgument("in_hi_space", "Login");
              redirect.AddControlArgument("in_hi_spaceID", 0);
              redirect.SetControl(LoginControl.STR_MVC_CLASS_NAME);
              redirect.AddControlArgument(LoginHTML.PARAM_DOLOGIN, true);
              redirect.AddControlArgument(LoginHTML.PARAM_USERNAME, nameOnly);
              redirect.AddControlArgument(LoginHTML.PARAM_USERPASS, usersPassword);
              redirect.AddControlArgument(LoginHTML.PARAM_AUTHSOURCE, "OMD Portal");
              return redirect;
    Password is set here:
         public Redirect OnAfterLogin(Object oUserSession, ApplicationData appData) {
                        String in_pw_userpass = appData.GetParameterValue("inpw_userpass"); // read from the login form
                        IXPRequest iXPRequest = _appData.GetRequest();
                        XPSession xPSession = iXPRequest.GetSession();
                        xPSession.SetAttribute("usersPassword", in_pw_userpass); // this is for passing it to LoginAgreementRepostControl
                        Redirect guestRedirect = new Redirect();
                        guestRedirect.SetLinkCreateNewSpace(LoginAgreementAS.STR_MVC_CLASS_NAME, null);
                        guestRedirect.SetControl(GuestLoginAgreementControl.STR_MVC_CLASS_NAME);
                        return guestRedirect;
    }

  • Can you change my charger it stop working and i dont know way?

    Someone

    Hi Alanlozano,
    We can't do anything for you. We are just users like you. If your device is still under warranty, take it (and the charger) to your Apple Store to have them take a look at it. If it is defective, they will replace it.
    Cheers,
    GB

  • Password Policy PEI

    .

    Well, then I would assume that the server thinks the users you imported via Passenger have already logged in at least once.
    If all you are trying to do is get these users to reset their password, select them all in Workgroup Manager, go to the Advanced tab, click Options under User Password Type. In there, you will get be able to individually set their OD password policies, i.e. Password Must be changed at next login.

  • Sun Directory Server Password Policy Problems

    Hi,
    I am using Sun Directory Server and Sun AM (2005Q1).
    We are using SUN DS to configure the password policy to expire user passwords after 30 days.
    Also, the warning has been set to "one day before expiry". However, when the warning IS displayed to the user and the user changes his/her password on display of the warning, even though the user's password expiration timestamp attribute contains a new timestamp (which is 30 days hence the date of change), on next login user is AGAIN thrown the warning that his/her password will expire in "HH hours: MM mins".
    I do not understand what needs to be done to fix this. Any help would be appreciated.

    How is the user authenticated ? Through Access Manager or directly to the Directory Server ?
    Access Manager can be configured to handle Password expiration, and so can Directory Server. I would advise you to check which system is actually throwing the warning.
    Regards,
    Ludovic

  • Password policy not working?

    I'm a little confused as to why a global OD password policy to change passwords on first login will not function. All users already have a single working password.
    Consequently, I've used a USER based policy in WM, but this asks the user to enter a new password and then doesn't allow any further progress.
    Any ideas?

    I believe that, in OID 10.1.2, the new password policy will not take effect until after the user's password has been changed.

  • Password policy through roles

    Hi,
    I have two password policies in my LDAP, mapped to the users through roles. One for active users and the other for inactive users. when i change the status from active to inactive, some times inactive password policy gets enabled, and some times it does not. The nsroles attribute in the user profile gets updated according to the role always, but the password policy subentry attribute is not getting updated sometimes.
    Can Anyone help me on this.
    Thanks in advance,
    Navanidhi

    This is probably a cache synchronization pb. Not something that I ever heard before though.
    How quick do you check the password policy after changing the user status ?
    Have you tried checking a minute or more after the change ?
    Ludovic.

  • I have reloaded Icloud on my Windows 7 PC and it just says it stopped working and closes the program after I enter my apple password, what can I do?

    I am unable to use Icloud on my Dell PC. I have uninstalled it twice and reloaded it. When I enter my Apple password, it tells me that it has stopped working and closes the program. What can I do to correct this.

    Hi MamaTabs,
    If you are having issues signing in to iCloud on your Windows machine, you may find some of the troubleshooting in the following article helpful:
    iCloud: Account troubleshooting
    http://support.apple.com/kb/ts3988
    Also, you may want to make sure that you are running the most recent version of iCloud Control Panel for Windows:
    Apple: iCloud Control Panel 3.1 for Windows
    http://support.apple.com/kb/dl1455
    Regards,
    - Brenden

  • Css background image stopped working despite no code change

    My background image was working fine. Then, without me changing the code, it stopped working. The URL I referred to exists and ends in .jpg.
    When I first load Thimble the background shows up for a split second, then disappears again.
    Here is the code
    background-color:#051c1c;
    background-image:url("http://www.rosesandrattlesnakes.com/cssbg.jpg");
    background-repeat: no-repeat;
    background-size: cover;
    background-attachment: fixed;
    background-position: top center;
    color:white;
    font-family:'Trebuchet MS', sans-serif;
    text-align:center;
    padding:0;
    I tried removing the quotation marks. That didn't fix it. Tried removing www. That didn't fix it. Tried making the link https. That didn't fix it.
    Also, hints doesn't work, whether the checkbox is ticked or not.
    Gotta say Thimble kinda sucks. Sorry

    Hello,
    I am glad to hear that your problem has been resolved.
    If you have not already, please mark this thread as solved by marking the solution.<br>
    This will help other users experiencing similar problems find help faster and more efficiently.
    I hope you continue using our products and thank you for contacting Mozilla Support.

  • Keyboad stops working after login

    Hey guys! I have windows 8.1 installed on my Lenovo Ideapad Z510. Recently, I have been experiencing problems with the keyboard. I can type in my password and log in, but the keyboard stops working after that. It used to stop working and then fix itself after a few minutes, but it completely stopped working yesterday.
    I have searched for solutions online and have tried almost everything from disabling filter keys to uninstalling the keyboard driver, but they did not make any difference.
    Please let me know if you can think of a solution. Any comments would be greatly appreciated.

    Try the on-screen keyboard and see if that works. I don't think this is your problem, but this morning after updating my Yoga from 8 to 8.1 my keyboard stopped working. But it has a touchscreen and then on-screen keyboard worked fine. I fixed the keyboard by moving the screen on the hinges. I have no idea what that did, but it fixed my problem.
    Hoov
    Microsoft MVP - Consumer Security
    SpywareHammer.com

  • IPlanet replication of password policy

    Hi,
    We are using iPlanet server 5.2 in replication mode.
    The problem is that an attribute "passwordRetryCount" does not get
    replicated.
    Could you please help as soon as possible ?
    Sachin

    Thanks a bunch !!!
    1) Is it to be added in cn=config i.e where we add other password policy parameters ?
    2) Also, will it work in case of multimaster environments i.e both our LDAP servers are suppliers ?

Maybe you are looking for

  • Automatic creation of Service Arrangements in SAP CRM 2007

    Dear all we're using SAP CRM Resource Planning with HCM integration, so get the Employee Master and requried Availability Info Types replicated from HCM via ALE. Unfortunately, between the creation of an Employee and the Time Distribution, a Service

  • Payment Advice errors ( window Main )

    Hi Gurus I am generating the payment advice for 2 different vendors based on their 2 different languages. CZ - language & EN ( Using the Texts in Recipients Langauge option) I am getting the following error during the payment program run with payment

  • Bonjour 1.0.6 will not open with Windows 7 RC

    I Have had this problem for months. I have a brand new 17" MacBook pro with windows 7 RC loaded via bootcamp. Also in my chain I have an Airport Extreme and a Dell Dimension 8100. The printer is hooked up directly to the Airport via USB. I can print

  • Button not working into a movieClip

    Hi i have made a movieclip and there is 2 buttons into that movieClips I have added Events on those buttons but those are not working. here my code links.demoButton.addEventListener(MouseEvent.CLICK.democlick) links.livelinkButton.addEventListener(Mo

  • How do i restore my ipod if it is not showing up on i-tunes?

    so u am i tunes and i know how to restore my ipod so i hit restore and then it wanted me to up grade my itunes so i said yes and it stopped the restore right in the middle and now all it is showing is the apple sigen and then the loading sigen under