Catch situations where attributes cannot be read due to required password change #25
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
When
slapo-ppolicy
is active on an OpenLDAP server, the relevant password policy specifiespasswordMustChange: TRUE
, and a given account haspwdReset: TRUE
, then, although it is possible to bind as the user, the only operation of substance allowed once bound is password reset. This change catches the resulting error code when another action is attempted, such as querying the user's own attributes.More details at https://linux.die.net/man/5/slapo-ppolicy