IBM Support

IV04372: KERBEROS USER UNABLE TO CHANGE PASSWD OF LOCAL USER WITH PWDADM APPLIES TO AIX 5300-12

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Kerberos user unable to change password of a local user
    with pwdadm
    
    The following error message will appear with pwdadm
    command :
    $ pwdadm -R files loc1
    Changing password for "loc1"
    foo's Password:    <  -- foo is kerberos user
    3004-604 Your entry does not match the old password.
    3004-664 You are not authorized to change "loc1's"
    password.
    

Local fix

Problem summary

  • Kerberos user unable to change password of a local user with
    pwdadm command. It gives an error message that
    $ pwdadm -R files loc1
    Changing password for "loc1"
    foo's Password:    <  -- foo is kerberos user
    3004-604 Your entry does not match the old password.
    3004-664 You are not authorized to change "loc1's" password.
    

Problem conclusion

  • when kerberos user try to change password of a local user,
    it fails to authenicate to KDC server. Added a condition
    that kerberos user can authenticate to KDC server and
    can change password of the local user.
    

Temporary fix

Comments

  • 5300-11 - use AIX APAR IV04424
    5300-12 - use AIX APAR IV04372
    6100-04 - use AIX APAR IV05606
    6100-05 - use AIX APAR IV05230
    6100-06 - use AIX APAR IZ99384
    6100-07 - use AIX APAR IZ99719
    7100-01 - use AIX APAR IV00577
    

APAR Information

  • APAR number

    IV04372

  • Reported component name

    AIX 5.3

  • Reported component ID

    5765G0300

  • Reported release

    530

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Submitted date

    2011-08-03

  • Closed date

    2011-08-03

  • Last modified date

    2013-04-16

  • APAR is sysrouted FROM one or more of the following:

    IV00577

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    AIX 5.3

  • Fixed component ID

    5765G0300

Applicable component levels

  • R530 PSY U849037

       UP11/12/01 I 1000

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11P","label":"APARs - AIX 5.3 environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"530","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
16 April 2013