unable to change user password

Bug #192593 reported by Fabrizio Balliano
6
Affects Status Importance Assigned to Milestone
likewise-open (Ubuntu)
Invalid
Undecided
Unassigned
Nominated for Hardy by Fabrizio Balliano

Bug Description

Binary package hint: likewise-open

once you joines an AD domain, users can authenticate correctly but they can't change their password with the "passwd" command (neither the "kpass" command works). The system keeps saying: "password does not match the rules" but there are no rules.

Revision history for this message
PaulSchulz (paulschulz) wrote :

This may not necessarily be a Ubuntu Bug.

AD administrators can set password rules, that need to be met for a password to be set correctly. I don't believe that these rules are easily available (other than through corporate documentation).

eg. The password must:
- not be a dictionary word.
- be longer than 8 characters.
- contain a combination of upper and lower case letters
- contain a number.

Please try changing the password that fits the above rules.

Revision history for this message
Fabrizio Balliano (fabrizio-balliano) wrote :

already tried and anyway within the AD control center, I disabled minimum lenght and all other checks

Revision history for this message
Fabrizio Balliano (fabrizio-balliano) wrote :

additional note: if I make a password expire from the DC, on the next login the user is prompted to change his password 'cause it's expired, and it works correctly. But it doesn't work when the user try changing it from shell.

Revision history for this message
Adam Sommer (asommer) wrote :

I wouldn't think that the passwd utility would be able to change a password in Active Directory. As far as I can tell passwd can only change shadow passwords, but I could be wrong about that. In order to change a password from the shell after joining an AD domain I would think another utility such as ldappasswd or smbpasswd would be needed.

Can you try smbpasswd?

Revision history for this message
Fabrizio Balliano (fabrizio-balliano) wrote :

maybe it's not the passwd command but i don't know what is lauched when the DC makes the password expire (in that case changing the password works).

anyway when you type "passwd" the system says something like "new NT password" or something like that (i don't have the real output now) thus passwd detect that there's something about the AD

Revision history for this message
Adam Sommer (asommer) wrote : Re: [Bug 192593] Re: unable to change user password

> anyway when you type "passwd" the system says something like "new NT
> password" or something like that (i don't have the real output now) thus
> passwd detect that there's something about the AD
>
>
That's pretty cool... I just tried passwd over an SSH session and it worked
fine, I guess since PAM is configured to use krb5 and the domain it works.
Do you see any errors in /var/log/auth.log when trying passwd?

--
Party On,
Adam

Revision history for this message
socceroos (skduff) wrote :

Hello,

This may be obvious, but if you go to 'Active Directory Users and Computers' in Administrative Tools on the AD server and double click on the username of the person who's password you're trying to change, and then click on the 'Account' tab is the box ticked on the user that says 'user cannot change password'?

I'm going to give the 'passwd' command on my computer a try this morning and see if it works for me.

Revision history for this message
socceroos (skduff) wrote :

I apologise for the double post

Revision history for this message
Fabrizio Balliano (fabrizio-balliano) wrote :

i saw that a new version of likewise-open was uploaded, I'm gonna retest everything asap, thank you!

Revision history for this message
Thierry Carrez (ttx) wrote :

Fabrizio: please let us know if you can reproduce with the version in hardy.

Changed in likewise-open:
status: New → Incomplete
Revision history for this message
Thomas E. Maleshafske (tmaleshafske) wrote :

I was unable to reproduce this bug in hardy with likewise-open version 4.0.5-0ubuntu3 installed.

Revision history for this message
Thierry Carrez (ttx) wrote :

Closed based on feedback.

Changed in likewise-open:
status: Incomplete → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.