cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1672
Views
0
Helpful
2
Replies

Implementing Password Expiration with ACS and Active Directory

drussell
Level 1
Level 1

I have a dialup client connection configured for MS-CHAP-V2 and radius with the ACS user profile pointing the WIN/2k. When I expire the password on the windows domain controller and have the user dial up, the user gets the expected prompt that the password is expired and is invited to enter a new password.

The password change fails with the ACS reporting that the "Windows 2000/NT password change failed" and the PC has a popup saying that the credentials do not allow the change.

Can anyone point me in the right direction? Is this a Windows problem an ACS?

2 Replies 2

sghosh
Level 1
Level 1

Hi,

We had some issues earlier about this where it works with Win98 clients only.

What kind of clients are you using ?

You need to enable logging on the ACS and create the package.cab file to see more details.

Thanks

Sujit

I opened a TAC case and found that the problem is a bug in the 3.1 code (CSCdz55509 ) that is fixed in 3.2 (July).

The workaround is to promote the ACS server to be a domain controller.