summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJan Cholasta <jcholast@redhat.com>2012-10-29 05:13:39 -0400
committerRob Crittenden <rcritten@redhat.com>2012-11-02 10:12:42 -0400
commit343e90eff6c93de536539f0abc3fe9e516beeb2b (patch)
tree6304d4355d134555845f853847f7905437cf5ec8
parent4cf3c2d5053bad8e62a80ffa586f8d5c1f7e41cd (diff)
downloadfreeipa.git-343e90eff6c93de536539f0abc3fe9e516beeb2b.tar.gz
freeipa.git-343e90eff6c93de536539f0abc3fe9e516beeb2b.tar.xz
freeipa.git-343e90eff6c93de536539f0abc3fe9e516beeb2b.zip
Reword description of the --passsync option of ipa-replica-manage.
https://fedorahosted.org/freeipa/ticket/3208
-rwxr-xr-xinstall/tools/ipa-replica-manage2
-rw-r--r--install/tools/man/ipa-replica-manage.16
2 files changed, 6 insertions, 2 deletions
diff --git a/install/tools/ipa-replica-manage b/install/tools/ipa-replica-manage
index d489275c..449138bd 100755
--- a/install/tools/ipa-replica-manage
+++ b/install/tools/ipa-replica-manage
@@ -86,7 +86,7 @@ def parse_options():
parser.add_option("--win-subtree", dest="win_subtree", default=None,
help="DN of Windows subtree containing the users you want to sync (default cn=Users,<domain suffix)")
parser.add_option("--passsync", dest="passsync", default=None,
- help="Password for the Windows PassSync user")
+ help="Password for the IPA system user used by the Windows PassSync plugin to synchronize passwords")
parser.add_option("--from", dest="fromhost", help="Host to get data from")
options, args = parser.parse_args()
diff --git a/install/tools/man/ipa-replica-manage.1 b/install/tools/man/ipa-replica-manage.1
index b1704c0b..83674390 100644
--- a/install/tools/man/ipa-replica-manage.1
+++ b/install/tools/man/ipa-replica-manage.1
@@ -108,7 +108,7 @@ Full path and filename of CA certificate to use with TLS/SSL to the remote serve
DN of Windows subtree containing the users you want to sync (default cn=Users,<domain suffix> \- this is typically what Windows AD uses as the default value) \- Be careful to quote this value on the command line
.TP
\fB\-\-passsync\fR=\fIPASSSYNC_PWD\fR
-Password for the Windows PassSync user. Required when using \-\-winsync. This does not mean you have to use the PassSync service.
+Password for the IPA system user used by the Windows PassSync plugin to synchronize passwords. Required when using \-\-winsync. This does not mean you have to use the PassSync service.
.TP
\fB\-\-from\fR=\fISERVER\fR
The server to pull the data from, used by the re\-initialize and force\-sync commands.
@@ -176,6 +176,10 @@ Create a winsync replication agreement:
.TP
Remove a winsync replication agreement:
# ipa\-replica\-manage disconnect windows.ad.example.com
+.SH "PASSSYNC"
+PassSync is a Windows service that runs on AD Domain Controllers to intercept password changes. It sends these password changes to the IPA LDAP server over TLS. These password changes bypass normal IPA password policy settings and the password is not set to immediately expire. This is because by the time IPA receives the password change it has already been accepted by AD so it is too late to reject it.
+.TP
+IPA maintains a list of DNs that are excempt from password policy. A special user is added automatically when a winsync replication agreement is created. The DN of this user is added to the excemption list stored in passSyncManagersDNs in the entry cn=ipa_pwd_extop,cn=plugins,cn=config.
.SH "EXIT STATUS"
0 if the command was successful