<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Directory Passwords Expiring on ESX HOST in VI: VMware ESX® 3.0 Discussions</title>
    <link>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242766#M4847</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a different solution for you and have seen this and addressed this in my environment.  When you add a user to ESX using the useradd command also issue this command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/usr/bin/chage -M 99999 username&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; This will keep the password from expiring on the ESX side&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Beaver&lt;/P&gt;&lt;P&gt;VMware Communities User Moderator&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;Co-Author of "VMware ESX Essentials in the Virtual Data Center" &lt;/P&gt;&lt;P&gt;Coming soon to a store near you!&lt;/P&gt;&lt;P&gt;*&lt;STRONG&gt;Virtualization is a journey, not a project.&lt;/STRONG&gt;*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 May 2008 14:33:52 GMT</pubDate>
    <dc:creator>sbeaver</dc:creator>
    <dc:date>2008-05-28T14:33:52Z</dc:date>
    <item>
      <title>Active Directory Passwords Expiring on ESX HOST</title>
      <link>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242763#M4844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Folks, we've configured our ESX 3.0.1 hosts to authenticate against Active Directory which has been working successfully for some time. The Active Directory accounts are set not to expire.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The hosts are now showing the message below, but when we change the password on the host it doesn't sync with domain, or sync over to Active Directory.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;You must change your password now and login again!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Changing password for user testacc1.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current Kerberos 5 password:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Changing password for testacc1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(current) UNIX password:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're left trying to logon again with the old password and the same message. We're going round in circles. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 13:47:59 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242763#M4844</guid>
      <dc:creator>Stuarty1874</dc:creator>
      <dc:date>2008-05-28T13:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Passwords Expiring on ESX HOST</title>
      <link>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242764#M4845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you paste your /etc/krb5.conf, we also auth against AD and if your password expires and requires a change, that should be done on a windows server on the AD domain. I've never seen this occur through the service console. I assume you used esxcfg-auth to configure your initial authentication with your domain controller?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 13:56:58 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242764#M4845</guid>
      <dc:creator>lamw</dc:creator>
      <dc:date>2008-05-28T13:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Passwords Expiring on ESX HOST</title>
      <link>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242765#M4846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sounds like your AD integration has issues.... Check out &lt;A href="http://www.astroarch.com/wiki/index.php/Remote_Authentication" target="test_blank"&gt;http://www.astroarch.com/wiki/index.php/Remote_Authentication&lt;/A&gt; for assistance. Note that to fully integrate so passwords work you need to have either winbind or secure ldap working. I know this works with winbind with no issues. However, the standard passwd command is NOT sufficient to change the password on the AD server , so you are really looking at a PAM change to make this work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is not really an ESX issue as much as it is a Linux issue as well. A good reference for this is the "Samba-3 By Example" book.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally however, if you do not have the proper linux tools installed you should change the pasword using any windows machine or the domain server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Best regards,&lt;/P&gt;&lt;P&gt;Edward L. Haletky&lt;/P&gt;&lt;P&gt;VMware Communities User Moderator&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;Author of the book 'VMWare ESX Server in the Enterprise: Planning and Securing Virtualization Servers', Copyright 2008 Pearson Education. CIO Virtualization Blog: &lt;A href="http://www.cio.com/blog/index/topic/168354" target="test_blank"&gt;http://www.cio.com/blog/index/topic/168354&lt;/A&gt;, As well as the Virtualization Wiki at &lt;A href="http://www.astroarch.com/wiki/index.php/Virtualization" target="test_blank"&gt;http://www.astroarch.com/wiki/index.php/Virtualization&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 14:12:53 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242765#M4846</guid>
      <dc:creator>Texiwill</dc:creator>
      <dc:date>2008-05-28T14:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Passwords Expiring on ESX HOST</title>
      <link>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242766#M4847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a different solution for you and have seen this and addressed this in my environment.  When you add a user to ESX using the useradd command also issue this command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/usr/bin/chage -M 99999 username&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; This will keep the password from expiring on the ESX side&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Beaver&lt;/P&gt;&lt;P&gt;VMware Communities User Moderator&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;Co-Author of "VMware ESX Essentials in the Virtual Data Center" &lt;/P&gt;&lt;P&gt;Coming soon to a store near you!&lt;/P&gt;&lt;P&gt;*&lt;STRONG&gt;Virtualization is a journey, not a project.&lt;/STRONG&gt;*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 14:33:52 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242766#M4847</guid>
      <dc:creator>sbeaver</dc:creator>
      <dc:date>2008-05-28T14:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Passwords Expiring on ESX HOST</title>
      <link>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242767#M4848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another note....  Did you add passwords when you created these accounts?  Just in case you should not need the AD passwords on ESX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Beaver&lt;/P&gt;&lt;P&gt;VMware Communities User Moderator&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;Co-Author of "VMware ESX Essentials in the Virtual Data Center" &lt;/P&gt;&lt;P&gt;Coming soon to a store near you!&lt;/P&gt;&lt;P&gt;*&lt;STRONG&gt;Virtualization is a journey, not a project.&lt;/STRONG&gt;*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 14:36:06 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242767#M4848</guid>
      <dc:creator>sbeaver</dc:creator>
      <dc:date>2008-05-28T14:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Passwords Expiring on ESX HOST</title>
      <link>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242768#M4849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the contents of my krb5.conf... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI level="1" type="ol"&gt;&lt;P&gt;Autogenerated by esxcfg-auth&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://communities.vmware.com/appdefaults"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;pam = {&lt;/P&gt;&lt;P&gt;debug = false&lt;/P&gt;&lt;P&gt;forwardable = true&lt;/P&gt;&lt;P&gt;krb4_convert = false&lt;/P&gt;&lt;P&gt;renew_lifetime = 36000&lt;/P&gt;&lt;P&gt;ticket_lifetime = 36000&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://communities.vmware.com/domain_realm"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;flhosp.net = FLHOSP.NET&lt;/P&gt;&lt;P&gt;example.com = EXAMPLE.COM&lt;/P&gt;&lt;P&gt;.example.com = EXAMPLE.COM&lt;/P&gt;&lt;P&gt;.domain.com= DOMAIN.COM&lt;/P&gt;&lt;P&gt;flhosp.net = FLHOSP.NET&lt;/P&gt;&lt;P&gt;domain.com = DOMAIN.COM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mydomain.myroot.net = MYDOMAIN.MYROOT.NET&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://communities.vmware.com/kdc"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;profile = /var/kerberos/krb5kdc/kdc.conf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://communities.vmware.com/libdefaults"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;default_realm = MYDOMAIN.MYROOT.NET&lt;/P&gt;&lt;P&gt;ticket_lifetime = 24000&lt;/P&gt;&lt;P&gt;dns_lookup_realm = false&lt;/P&gt;&lt;P&gt;default_realm = DOMAIN.COM&lt;/P&gt;&lt;P&gt;dns_lookup_kdc = false&lt;/P&gt;&lt;P&gt;&lt;A href="https://communities.vmware.com/logging"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;default = FILE:/var/log/krb5libs.log&lt;/P&gt;&lt;P&gt;admin_server = FILE:/var/log/kadmind.log&lt;/P&gt;&lt;P&gt;kdc = FILE:/var/log/krb5kdc.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://communities.vmware.com/realms"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;MYDOMAIN.MYROOT.NET = {&lt;/P&gt;&lt;P&gt; admin_server = mydomain.myroot.net:4749&lt;/P&gt;&lt;P&gt; default_domain = mydomain.myroot.net&lt;/P&gt;&lt;P&gt; kdc = dc1.mydomain.myroot.net:88&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also copy krb.conf during install....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI level="1" type="ol"&gt;&lt;P&gt;Autogenerated by esxcfg-auth&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acl_file = /var/kerberos/krb5kdc/kadm5.acl&lt;/P&gt;&lt;P&gt;dict_file = /usr/share/dict/words&lt;/P&gt;&lt;P&gt;admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab&lt;/P&gt;&lt;P&gt;v4_mode = nopreauth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I aslo copy krb5.realms during install...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI level="1" type="ol"&gt;&lt;P&gt;Autogenerated by esxcfg-auth&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M01DOMAIN.MYROOT.NET = {&lt;/P&gt;&lt;P&gt;master_key_type = des-cbc-crc&lt;/P&gt;&lt;P&gt;supported_enctypes = des3-cbc-raw:normal des3-cbc-raw:norealm&lt;/P&gt;&lt;P&gt;des3-cbc-raw:onlyrealm des3-cbc-sha1:normal&lt;/P&gt;&lt;P&gt;des3-cbc-sha1:norealm des3-cbc-sha1:onlyrealm&lt;/P&gt;&lt;P&gt;des-cbc-crc:v4 des-cbc-crc:afs3&lt;/P&gt;&lt;P&gt;des-cbc-crc:normal des-cbc-crc:norealm&lt;/P&gt;&lt;P&gt;des-cbc-crc:onlyrealm des-cbc-md4:v4&lt;/P&gt;&lt;P&gt;des-cbc-md4:afs3 des-cbc-md4:normal&lt;/P&gt;&lt;P&gt;des-cbc-md4:norealm des-cbc-md4:onlyrealm&lt;/P&gt;&lt;P&gt;des-cbc-md5:v4 des-cbc-md5:afs3&lt;/P&gt;&lt;P&gt;des-cbc-md5:normal des-cbc-md5:norealm&lt;/P&gt;&lt;P&gt;des-cbc-md5:onlyrealm des-cbc-raw:v4&lt;/P&gt;&lt;P&gt;des-cbc-raw:afs3 des-cbc-raw:normal&lt;/P&gt;&lt;P&gt;des-cbc-raw:norealm des-cbc-raw:onlyrealm&lt;/P&gt;&lt;P&gt;des-cbc-sha1:v4 des-cbc-sha1:afs3&lt;/P&gt;&lt;P&gt;des-cbc-sha1:normal des-cbc-sha1:norealm&lt;/P&gt;&lt;P&gt;des-cbc-sha1:onlyrealm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The accounts are created during install by using the following.  I don't set a password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;useradd -m &lt;A href="account name"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas? Do I need to copy the krb5.realms &amp;amp; krb.conf ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 May 2008 12:22:48 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242768#M4849</guid>
      <dc:creator>Stuarty1874</dc:creator>
      <dc:date>2008-05-30T12:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Passwords Expiring on ESX HOST</title>
      <link>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242769#M4850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds like you just enabled kerberos auth logins, you haven't done full AD integration with WinBind and pam.  In other words, are you creating local accounts for each user?  Without winbind you won't be able to honor the Windows password controls.  You've probably just passed the local password expiration policy of your local accounts (which are still authenticating with AD Kerberos).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As some posters pointed out, you need to change the local password expiration default for new users. (Disable it for new users).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;esxcfg-auth --passmaxdays=-1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, this will not affect existing users IIRC. You'll have to update existing users as well I believe. (Disable it for existing user).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;chage -M -1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your other option is to "upgrade" your AD integration to full winbind integration as a few other posters indicated.  The root and vpxuser account have no aging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm guessing esxcfg-auth --passmaxdays may just edit /etc/login.defs (usual place where the password expiration default settings are kept).  Have to take a look at it when I get a chance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 May 2008 12:47:06 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242769#M4850</guid>
      <dc:creator>stumpr</dc:creator>
      <dc:date>2008-05-30T12:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Passwords Expiring on ESX HOST</title>
      <link>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242770#M4851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know this is an older thread but it seems like a good place for my question. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I run batch script on my vCenter servers which populates a text file with a list of users from an AD Group "ESX-Admins" . This script runs nightly and the file is created in a directory under a Windows file services for Unix NFS share, which is also on my vCenter. The share is then mounted to all my ESX hosts as &lt;STRONG&gt;/vmfs/volumes/depot&lt;/STRONG&gt; and is used as a central repository for shared files scripts etc. I then run a bash script on the ESX hosts which deletes all the accounts on the ESX host excluding a handful of service accounts and then adds the users listed in the text file to the ESX host using &lt;STRONG&gt;useradd &amp;amp;lt;username&amp;amp;gt;&lt;/STRONG&gt; . Users then authenticate using AD username and password. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any security issue with never assigning a local password for a newly created user account using &lt;STRONG&gt;useradd &amp;amp;lt;username&amp;amp;gt;&lt;/STRONG&gt; without using the option &lt;STRONG&gt;-p&lt;/STRONG&gt; or later running the &lt;STRONG&gt;passwd&lt;/STRONG&gt; command? The account seems to work without issue and does not allow a log in without the correct AD password. From what I have read it seems an account created with &lt;STRONG&gt;useradd&lt;/STRONG&gt; is not actually enabled locally until a password is set?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Feb 2009 01:12:53 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VI-VMware-ESX-3-0-Discussions/Active-Directory-Passwords-Expiring-on-ESX-HOST/m-p/242770#M4851</guid>
      <dc:creator>korman</dc:creator>
      <dc:date>2009-02-21T01:12:53Z</dc:date>
    </item>
  </channel>
</rss>

