Most of the users are from an OpenDAP server, and users log in via SSH. Some users use a key to log in, some use a password.
I have set up a password policy for LDAP, so users may become locked in LDAP (by policy).
So I wonder: Can I make OpenSSH deny key logins for users that are locked in LDAP?
Likewise: OpenLDAP handles the date of last successful authentication (authTimestamp or pwdLastSuccess) to detect "idle" accounts; can I make OpenSSH to update these attributes when authenticating via key (so that the accounts won't be locked due to being "idle")?
As i understand it, OpenSSH would have to authenticate against LDAP to make the server update the attributes. Probably not possible, but anyway...