Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-110204

Enable external password reset agents to use ipa_pwd_extop in RHEL IdM

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • None
    • 1
    • rhel-idm-ipa
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • IPA: RHELs for 10.2 and 9.8
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Goal

      As an IdM administrator, I want to configure external password reset agents (e.g., CyberArk) to use the ipa_pwd_extop mechanism, so that privileged password resets can be performed securely without forcing users to change their password at next login

      Acceptance criteria

      Acceptance criteria

      • Verify that an external agent can authenticate with a privileged DN.
      • Verify that the agent can reset a user’s password using ipa_pwd_extop.
      • Verify that the user is not forced to reset their password upon next login.
      • Verify that audit/logging records the reset action.
      • Verify that documentation clearly explains setup and security best practices.

              frenaud@redhat.com Florence Renaud
              ftrivino@redhat.com Francisco Trivino Garcia
              Florence Renaud Florence Renaud
              Anuja More Anuja More
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: