Details
-
Improvement
-
Status: In Progress
-
Minor
-
Resolution: Unresolved
-
None
-
None
-
None
Description
Currently, password policy is not applied centrally, let alone per "realm" or subtree/subtree refinement. The Change Password protocol provider enforces a best-practice password policy. However, this is bypassed during other password sets, such as during LDIF load or LDAP add and modify operations.
Password policy enforcement should move to the core, for reuse by other mechanisms for password changes.
Password policy is currently enforced in the CheckPasswordPolicy IoHandlerCommand.