When checking the user's password during PAM_PRELIM_CHECK, if we get back "expired credentials", we should attempt to acquire {{{kadmin/getpw}}} credentials. If that succeeds, return success and use these credentials during the normal CHAUTHTOK request.
It is already done this way
resolution: => invalid status: new => closed
Manual tests are already written to cover expired passwords for all supported auth providers.
tests: 1 => 0 testsupdated: 0 => 1
Fields changed
rhbz: => 0
Metadata Update from @sgallagh: - Issue assigned to sbose - Issue set to the milestone: SSSD 1.1
SSSD is moving from Pagure to Github. This means that new issues and pull requests will be accepted only in SSSD's github repository.
This issue has been cloned to Github and is available here: - https://github.com/SSSD/sssd/issues/1389
If you want to receive further updates on the issue, please navigate to the github issue and click on subscribe button.
subscribe
Thank you for understanding. We apologize for all inconvenience.