On Mon, Oct 04, 2021 at 07:05:46AM -0000, Tiziano Müller wrote:
Hi everyone,
I just migrated a directory over from OpenLDAP and would now like to turn on the Password Policy functionality `passwordMustChange`. Unfortunately since none of the users has `pwdReset: FALSE` set, this would force every user to change their password. When trying to set `pwdReset: FALSE` for a user I get the error "server unwilling to comply". Is there a way I can still set the attribute for each of the existing users? Such that only from now on when an admin sets a password the user has to set it?
$ man -s 5 shadow
Check the section on "date of last password change"