Q&A: Which password policy applies to the different password change and reset workflows?

Question

How do the UDM password policy and the Samba domain password policy interact in UCS, and which policy applies to the different password change and reset workflows?

Answer

In a UCS domain with Samba installed, two separate password policy systems exist: the UDM password policy and the Samba domain password policy.

It is recommended to configure both policies consistently.

Password operation Processing path Applied policy Samba check password script
User changes own password in Portal / UMC PAM / Kerberos → Samba AD DC Samba domain policy Yes
User changes own password in End User Self Service PAM / Kerberos → Samba AD DC Samba domain policy Yes
User changes password with kpasswd Kerberos → Samba AD DC Samba domain policy Yes
User changes password from a Windows domain client Samba AD DC Samba domain policy Yes
End User Self Service “Forgot password” Self Service Backend → UDM UDM password policy No
Administrator resets a password in UMC / UDM UDM UDM password policy No
UCS@school administrator sets a temporary password UDM UDM password policy No
UCS@school user replaces the temporary password at next login PAM / Kerberos → Samba AD DC Samba domain policy Yes

The important distinction is not only which user interface is used, but whether the user changes their own password or whether the password is reset through an administrative workflow.

UDM password policy

The UDM password policy applies when a password is set or reset through UDM-based workflows, for example:

  • UMC / UDM administrative password resets
  • End User Self Service “Forgot password”
  • UCS@school password reset by a school administrator

If “Password quality check” is enabled in the UDM policy, additional checks can be configured through the password/quality/* UCR variables.

password/quality/mspolicy=true enables Microsoft-style complexity checks in addition to the other UDM password quality checks.

With

ucr set password/quality/mspolicy=sufficient

the Microsoft-style checks are considered sufficient and the remaining cracklib-based checks are skipped when they pass.

This does not apply the Samba domain password policy. The checks are performed independently on the UDM side.

Samba domain password policy

When Samba is installed, the Samba domain password policy applies when users change their own passwords.

This includes:

  • Portal / UMC password changes
  • Regular End User Self Service password changes with the current password
  • Windows domain clients
  • Kerberos password changes such as kpasswd

Additional password rules can be implemented with Samba’s check password script.

For configuration details and an example script, see:

How-to: Configure a Samba check password script in UCS

End User Self Service

The End User Self Service provides two technically different password workflows:

  • “Change password”: The user knows the current password. The change is performed through PAM / Kerberos and, with Samba installed, the Samba domain password policy applies.
  • “Forgot password”: After successful token verification, the Self Service Backend resets the password through UDM. No regular Kerberos password change is performed, and the UDM password policy applies.

UCS@school

When a school administrator resets a user’s password, the temporary password is set through UDM and follows the UDM password policy.

If “User has to change password on next login” is enabled, the user subsequently chooses a new private password. This second step is a user-initiated password change and follows the Samba domain password policy when Samba is installed.

2 Likes

This topic was automatically closed after 24 hours. New replies are no longer allowed.