Account lockout policy is not working

Andrew Bartlett abartlet at
Thu Sep 5 05:09:43 CEST 2013

On Wed, 2013-09-04 at 21:27 -0500, Ricky Nance wrote:
> The DC level gpo's are still being implemented, and pdbedit is made for the
> older samba 3 style setups (non AD controller that is). For AD you should
> use samba-tool for everything management wise. Take a look at `samba-tool
> domain passwordsettings`

That's a nasty and annoying bug.  Can someone please file it in

The issue is that pdb_samba_dsdb does not read and write the sam.ldb in
this instance.  Instead, it just calls into the 'source3' account policy
code.  This is silly, we should handle this interface correctly or not
at all.  That way, this aspect of pdbedit and net would work just as
much as the other aspects do. 

Andrew Bartlett

Andrew Bartlett
Authentication Developer, Samba Team 
Samba Developer, Catalyst IT         

More information about the samba-technical mailing list