Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

6
  • why not just change the password of the user? Commented Feb 4, 2014 at 16:18
  • That effectively changes their state (unable to login), but it doesn't serve as a marker or anything we can check. For example, if we want to get a list of all users who are deactivated, we can search for anyone without a valid loginShell. Commented Feb 4, 2014 at 16:27
  • In my short memories playing with LDAP, you can ad almost every thing you wnat to a user, why not a flag disable and in the same time change there password and shell Commented Feb 4, 2014 at 16:29
  • Yeah, we could definitely add a "isDeactivated" LDAP attribute or something like that, but then I'm not sure how to perform that check upon every login attempt. Commented Feb 4, 2014 at 16:30
  • 2
    This SF Q&A looks related: serverfault.com/questions/176834/how-to-disable-an-ldap-account Commented Feb 4, 2014 at 17:09