Project

General

Profile

Actions

Task #2843

open

Send attribute to system together with the password for all operations

Added by Alena Peterová over 3 years ago. Updated over 2 years ago.

Status:
New
Priority:
High
Assignee:
-
Category:
Provisioning
Target version:
-
Start date:
05/31/2021
Due date:
% Done:

0%

Estimated time:
16.00 h
Owner:

Description

After discussion with the team, the current implementation of the checkbox "Include only when password is changed" (#1787) doesn't cover all the use cases we need, because it's not sent when a new account is created.
Please change the behaviour so that the attribute is sent to the system only together with password = literally always when the PASSWORD is present in the attributes sent to the system.

Use cases:
  • pwdLastSet=true - when IdM sets this, AD will prompt users to change their password when they first login. So we want to send this attribute for newly created accounts and after reseting the password of the account
  • other metadata related to the password - initialization vector, timestamp with the password validity,...
Actions

Also available in: Atom PDF