How to modify the Apigee default LDAP policy

Viewed 194

I want to customize the pwpolicy of my Apigee environment and in particular the default one set up for users.

I followed this from the documentation: https://docs.apigee.com/private-cloud/v4.18.05/managing-default-ldap-password-policy-api-management

but it doesn't work. there is no effect on the policy when I create a new user. The default policy is part of an overlay so it should apply it by default no need to add this to user directly if I well understood.

To test I only modified the pwdMinLength as follow :

 # default, pwpolicies, apigee.com
dn: cn=default,ou=pwpolicies,dc=apigee,dc=com
objectClass: person
objectClass: pwdPolicy
objectClass: top
cn: default
pwdAttribute: userPassword
sn: dummy value
pwdExpireWarning: 604800
pwdInHistory: 3
pwdLockout: TRUE
pwdLockoutDuration: 300
pwdFailureCountInterval: 300
pwdMaxAge: 0
pwdMaxFailure: 3
pwdMinLength: 11

in a /tmp/defaultModified file

then I replaced the current default policy by this one and restarted

ldapdelete -H ldap://localhost:10389 -x -D "cn=manager,dc=apigee,dc=com" -W "cn=default,ou=pwpolicies,dc=apigee,dc=com"
ldapadd -x -w $ldappassword -D "cn=manager,dc=apigee,dc=com" -H "ldap://localhost:10389/" -f "/tmp/defaultModified"

after restart when I create a new user the min length is still 8 chars

Does someone have an idea ?

0 Answers
Related