Question
How do the UDM password policy and the Samba domain password policy interact in UCS, and which policy applies to the different password change and reset workflows?
Answer
In a UCS domain with Samba installed, two separate password policy systems exist: the UDM password policy and the Samba domain password policy.
It is recommended to configure both policies consistently.
| Password operation | Processing path | Applied policy | Samba check password script |
|---|---|---|---|
| User changes own password in Portal / UMC | PAM / Kerberos → Samba AD DC | Samba domain policy | Yes |
| User changes own password in End User Self Service | PAM / Kerberos → Samba AD DC | Samba domain policy | Yes |
User changes password with kpasswd |
Kerberos → Samba AD DC | Samba domain policy | Yes |
| User changes password from a Windows domain client | Samba AD DC | Samba domain policy | Yes |
| End User Self Service “Forgot password” | Self Service Backend → UDM | UDM password policy | No |
| Administrator resets a password in UMC / UDM | UDM | UDM password policy | No |
| UCS@school administrator sets a temporary password | UDM | UDM password policy | No |
| UCS@school user replaces the temporary password at next login | PAM / Kerberos → Samba AD DC | Samba domain policy | Yes |
The important distinction is not only which user interface is used, but whether the user changes their own password or whether the password is reset through an administrative workflow.
UDM password policy
The UDM password policy applies when a password is set or reset through UDM-based workflows, for example:
- UMC / UDM administrative password resets
- End User Self Service “Forgot password”
- UCS@school password reset by a school administrator
If “Password quality check” is enabled in the UDM policy, additional checks can be configured through the password/quality/* UCR variables.
password/quality/mspolicy=true enables Microsoft-style complexity checks in addition to the other UDM password quality checks.
With
ucr set password/quality/mspolicy=sufficient
the Microsoft-style checks are considered sufficient and the remaining cracklib-based checks are skipped when they pass.
This does not apply the Samba domain password policy. The checks are performed independently on the UDM side.
Samba domain password policy
When Samba is installed, the Samba domain password policy applies when users change their own passwords.
This includes:
- Portal / UMC password changes
- Regular End User Self Service password changes with the current password
- Windows domain clients
- Kerberos password changes such as
kpasswd
Additional password rules can be implemented with Samba’s check password script.
For configuration details and an example script, see:
How-to: Configure a Samba check password script in UCS
End User Self Service
The End User Self Service provides two technically different password workflows:
- “Change password”: The user knows the current password. The change is performed through PAM / Kerberos and, with Samba installed, the Samba domain password policy applies.
- “Forgot password”: After successful token verification, the Self Service Backend resets the password through UDM. No regular Kerberos password change is performed, and the UDM password policy applies.
UCS@school
When a school administrator resets a user’s password, the temporary password is set through UDM and follows the UDM password policy.
If “User has to change password on next login” is enabled, the user subsequently chooses a new private password. This second step is a user-initiated password change and follows the Samba domain password policy when Samba is installed.