Premchand Singh
Premchand Singh

Reputation: 23

How to resolve LDAP: error code 19 - pwdFailureTime: no user modification allowed for OPEN LDAP

While unlocking an account I am getting error message as : LDAP: error code 19 - pwdFailureTime: no user modification allowed

Tried giving different values for the attribute 'pwdAccountlockedtime' on LDAP managed system from apache Directory Studio, but getting same error message.

Upvotes: 0

Views: 2510

Answers (1)

ZoltanB
ZoltanB

Reputation: 109

Error Code 19 : constraintViolation
"Indicates that the client supplied an attribute value that does not conform to the constraints placed upon it by the data model." See OpenLdap Doc
You are not allowed to change pwdFailureTime. It is defined in the passwordpolicy.
Unlock User:
Modify userPassword with admin Privileges. Depending on your policy settings (passwordMustChange, etc.) user should change his initial password to a final (not initial Password). Then will be nsAccountLock "automatically" cleared.

Upvotes: 0

Related Questions