mirror of
https://github.com/laurivosandi/certidude.git
synced 2026-04-25 00:25:57 +03:00
[GH-ISSUE #45] Relevant OCSP response if user account disabled in AD #37
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/certidude-laurivosandi#37
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @laurivosandi on GitHub (Mar 1, 2018).
Original GitHub issue: https://github.com/laurivosandi/certidude/issues/45
Currently OCSP responder returns ok regardless of user account status in AD. Certidude should have config to handle this
@plaes commented on GitHub (Mar 1, 2018):
Also two extra scenarios where
UserAccountControlattribute is not enough:accountExpiresattributelockoutTimeAnd then there's also
pwdLastSetmess because password expiration is read from domain root object'spwdMaxAgeattribute, but one should take account theneverExpiresbit inUserAccountControl. Though I guess Certidude should not care about the password...