DirectSecure, Authentication Service, Auditing and Monitoring Service
000007107
A new AD user has the "Change password on first login" box checked. If they try to SSH into a *nix machine as their first login, they get booted out. If they log into a Windows machine in the same AD network, they are prompted to change the password. After they change it, they can SSH into the *nix machine without any problem.
Applies to: All version of Centrify Server Suite
Question: When an Active Directory user account is created with "change password at first login" is checked, why isn't the user prompted to change the password when they use SSH to login to a UNIX machine as their first login? The SSH session just disconnects.
Answer: This is usually an issue with the kerberos ports being closed. When that happens, the system forces the account to use NTLM. In a one-way cross forest trust using NTLM authentication, Centrify isn't currently able to support the password expiration/change sequence.
The kerberos ports needed are: Port 88 - UDP/TCP for Kerberos Auth Port 464 - UDP/TCP for Kerberos Change Password