As an IdM administrator, I want clear and consolidated documentation for configuring external agents to perform privileged password resets so that third-party tools (e.g., CyberArk) can integrate securely with FreeIPA.
Currently, FreeIPA supports password synchronization from Active Directory using the Passsync plugin. This plugin leverages the ipa_pwd_extop feature, which treats specific LDAP bind DNs as Directory Manager equivalents, allowing password resets without forcing users to change passwords upon next login.
However, there is no clear, consolidated documentation detailing how to configure external agents to perform such privileged password resets. This gap prevents third-party vendors, such as CyberArk, from integrating their own secure password reset solutions with FreeIPA.
The goal of this request is to create comprehensive, user-friendly documentation that describes the setup and configuration steps required for external password reset agents to leverage this mechanism safely and effectively.
Something more than this? https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/managing_idm_users_groups_hosts_and_access_control_rules/managing-user-passwords-in-idm_managing-users-groups-hosts#enabling-password-reset-in-idm-without-prompting-the-user-for-a-password-change-at-the-next-login_managing-user-passwords-in-idm
@rcritten yes, I implemented sysaccounts as an IPA object, see https://github.com/freeipa/freeipa/pull/7908 for more details.
Metadata Update from @abbra: - Issue assigned to abbra
Design document: https://freeipa--7908.org.readthedocs.build/en/7908/designs/sysaccounts.html
master:
Metadata Update from @frenaud: - Custom field rhbz adjusted to https://issues.redhat.com/browse/RHEL-110204
ipa-4-12:
Metadata Update from @frenaud: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
ipa-4-13: