-
Story
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
1
-
rhel-idm-ipa
-
None
-
False
-
False
-
-
None
-
IPA: RHELs for 10.2 and 9.8
-
None
-
None
-
Unspecified
-
Unspecified
-
Unspecified
-
None
Goal
As an IdM administrator, I want to configure external password reset agents (e.g., CyberArk) to use the ipa_pwd_extop mechanism, so that privileged password resets can be performed securely without forcing users to change their password at next login
Acceptance criteria
Acceptance criteria
- Verify that an external agent can authenticate with a privileged DN.
- Verify that the agent can reset a user’s password using ipa_pwd_extop.
- Verify that the user is not forced to reset their password upon next login.
- Verify that audit/logging records the reset action.
- Verify that documentation clearly explains setup and security best practices.