Password Policy change question
Hi!
If I have a policy that dictates that a user must change his password
every 30 days, then NMAS will set the passwordexpirationtime attribute
to todays date + 30 days if the user would change his password today right?
If I then go and change the policy and set the expiration time to 60
days what would happen when the user would login 30 days from now?
I'm assuming here that changing the policy doesn't mean that a process
kicks off that goes through the entire directory and updates the
passwordexpirationtime attribute?
Would NMAS check the policy and the timestamp of the password and say
OK, you have thirty more days to go before you have to change your
password, or would it read the passwordexpirationtime and say STOP, your
password has expired. Which wins here?
Hope you understand my question,
Thanks
|