Submitting forms on the support site are temporary unavailable for schedule maintenance. If you need immediate assistance please contact technical support. We apologize for the inconvenience.
Smartcard Users Getting Password Expired Error After Upgrading
Description
Smartcard users authenticating using Authentication Services recieve a "password expired" error after upgrading Authentication Services to version 4.2.4 or higher.
Cause
Due to some recent fixes post-version 4.2.1, access control has changed.
Password prompts are coming from vasd and not from the library.
The vasd daemon checks and then insists on a password change.
Even though pam_vas_smartcard handles the authentication, pam_vas handles the access control.
Resolution
Within the pam_vas.so module no_passwordexpired_check can be supplied on the account line so that the expired password iis no longer checked for.
The setting will go into the /etc/pam.d/password-auth file in the account section as follows:
Your Request will be reviewed by our technical reviewer team and, if approved, will be added as a Topic in our Knowledgebase.
Welcome to One Identity Support
You can find online support help for*product* on an affiliate support site. Click continue to be directed to the correct support content and assistance for *product*.
The One Identity Portal no longer supports IE8, 9, & 10 and it is recommended to upgrade your browser to the latest version of Internet Explorer or Chrome.