Koozali.org: home of the SME Server

password expiry

Offline brianr

  • *
  • 988
  • +2/-0
password expiry
« on: January 03, 2006, 12:27:38 PM »
I am having trouble with a WIndows network, domain logging into sme 6.0.1 (and updates).

Every now and again we get a message at login on one workstation oir another saying that the password will expire in N days (where n = 10, or 11, etc).  So far nothing seems to have actually expired!

If you choose the option to renew the password, this fails.

I have googled the problem, and can see that there can be some issues with samba and pam, but do not feel I understand it all enought to fiddle with the parameters.

Does anyone have any ideas on this problem?
Brian j Read
(retired, for a second time, still got 2 installations though)
The instrument I am playing is my favourite Melodeon.
.........

alejandro

password expiry
« Reply #1 on: January 03, 2006, 03:45:07 PM »
Just a question before answers.
The expiration message is from windows or from server?

Offline brianr

  • *
  • 988
  • +2/-0
password expiry
« Reply #2 on: January 03, 2006, 04:19:05 PM »
from windows, at login time.
Brian j Read
(retired, for a second time, still got 2 installations though)
The instrument I am playing is my favourite Melodeon.
.........

alejandro

password expiry
« Reply #3 on: January 03, 2006, 04:36:45 PM »
Are you sure you are using domain logon?
If your pasword is expiring or windows is advicing it will expire, it refers to a local user of the window's domain, not for the sme's domain.
Non local domain user's credentials have no expiration check at windows workstation logon stage.
check in Control Panel > Users
You should have
user ---------domain------------- group
"admin" ---"pc-domain"---------"Administrators"
"you"-----"sme's domain" ------"whatever group"

Offline brianr

  • *
  • 988
  • +2/-0
password expiry
« Reply #4 on: January 03, 2006, 04:54:25 PM »
This is an installation of about 15 workstations, and they have all been configured (by me) to logon to the SMEServer by domain.  Previously they logged onto a Windows 200 server.  There is only the SMeserver on the network.

In control panel/users  I can only see the local users (which does not include the username that we logon to via the domain).

The Pcs are on XP Pro, with the very latest in updates.
Brian j Read
(retired, for a second time, still got 2 installations though)
The instrument I am playing is my favourite Melodeon.
.........

Offline ansentry

  • ***
  • 118
  • +0/-0
password expiry
« Reply #5 on: January 03, 2006, 10:33:53 PM »
brianr,

A question if you don’t mind.

On your XP PC’s have you made the required changes to the registry?

If not, then the XP PC will not connect correctly to the SME Domain.

If I am correct and you have not made the changes, post back and I will detail the procedure that I follow when I do this.
Regards,

John A

Offline brianr

  • *
  • 988
  • +2/-0
password expiry
« Reply #6 on: January 03, 2006, 10:57:16 PM »
I did the registry change when I installed the systems, as you say, Xp will not recognise the domain controller without it.

The PCs and network have been in use sucessfully by the users for well over 2 months, its just that we get this "password expiry" warning every now and again on some of the PCs.
Brian j Read
(retired, for a second time, still got 2 installations though)
The instrument I am playing is my favourite Melodeon.
.........

Offline ansentry

  • ***
  • 118
  • +0/-0
password expiry
« Reply #7 on: January 03, 2006, 11:16:53 PM »
Brian,

Have you added the domain users to User accounts in windows?

One each PC that I setup I only have the Administrator as a local user. I then add the domain users to the PC. I then have a login script on the SME that connects each user to their correct drives.
Regards,

John A

Offline vincentmeek

  • *
  • 29
  • +0/-0
    • Triple Point Solutions
password expiry
« Reply #8 on: January 04, 2006, 01:54:00 AM »
If the PCs were previously connected to a 2000 server domain, it maybe the password/security policy from that server.  If so search M$ site for instructions on removing the policies fom these PCs.

Just a thought. :idea:
Vincent Meek
Network Consultant