Enforce Expiration Dates¶
This is to be done on the login node — compute nodes should already deny SSH entirely (see SSH Access Control).
Update /etc/pam.d/common-account to enable shadow expiration checking:
Change this line:
To this:
Edit the SSSD configuration file:
Add these parameters to your [domain/example] section:
ldap_account_expire_policy = shadow
ldap_pwd_policy = shadow
ldap_access_order = expire
ldap_user_shadow_last_change = shadowLastChange
ldap_user_shadow_expire = shadowExpire
Pubkey auth bypasses this
Pubkey authentication bypasses LDAP's shadowExpire check entirely, since PAM's account phase isn't consulted the same way. See Pubkey Exception for a Blocked User for why that matters and how it's handled.