1 <samba:parameter name="check password script"
5 xmlns:samba="http://www.samba.org/samba/DTD/samba-doc">
7 <para>The name of a program that can be used to check password
8 complexity. The password is sent to the program's standard input.</para>
10 <para>The program must return 0 on a good password, or any other value
11 if the password is bad.
12 In case the password is considered weak (the program does not return 0) the
13 user will be notified and the password change will fail.</para>
15 <para>In Samba AD, this script will be run <emphasis>AS ROOT</emphasis> by
16 <citerefentry><refentrytitle>samba</refentrytitle> <manvolnum>8</manvolnum>
17 </citerefentry> without any substitutions.</para>
19 <para>Note that starting with Samba 4.11 the following environment variables are exported to the script:</para>
23 SAMBA_CPS_ACCOUNT_NAME is always present and contains the sAMAccountName of user,
24 the is the same as the %u substitutions in the none AD DC case.
28 SAMBA_CPS_USER_PRINCIPAL_NAME is optional in the AD DC case if the userPrincipalName is present.
32 SAMBA_CPS_FULL_NAME is optional if the displayName is present.
36 <para>Note: In the example directory is a sample program called <command moreinfo="none">crackcheck</command>
37 that uses cracklib to check the password quality.</para>
41 <value type="default"><comment>Disabled</comment></value>
42 <value type="example">/usr/local/sbin/crackcheck</value>