Specify NSS password overrides

Specify the passwd override entries you want to use in place of the entries in the local /etc/passwd file.

Defining override filters can give you fine-grain control over the user accounts that can access a local computer. You can also use override controls to modify the information for specific fields in each /etc/passwd entry on the local computer. For example, you can override the user ID, primary group ID, default shell, or home directory for specific login accounts on the local computer without modifying the account entry itself.

The syntax for overriding passwd entries is:

[+,-][user,@group]:name:passwd:uid:gid:gecos:home:shell

The name can be an Active Directory group name, a Centrify DirectControl zone name, or some other container name. You may also specify an Active Directory user principal name (UPN) instead of the zone name.

If you don't specify override information for a field, the information from the local /etc/passwd file is used. You cannot specify override information for the password hash field, however. Any changes to this field in the override file are ignored and do not affect Centrify DirectControl user passwords.

In NIS, the @ symbol denotes a netgroup name. In this case, the @ symbol denotes a AD group name (zone or CN). Group Policy can be used to assign computers to groups and apply policy to them, thus replacing the netgroup host/user/group triplet mechanism.

Entries in the override file are evaluated in order from first to last with the first match taking precedence. This means the system will only use the first entry that matches a particular user.

An empty (or non-existent) file is the equivalent of adding one line: +:::::::. If you check the "Include all other AD users" box, a +::::::: will be appended after the specific entries.

This group policy modifies the nss.passwd.override setting in the Centrify DirectControl configuration file.

For more information about overriding passwd entries, see the sample password override file /etc/centrifydc/passwd.ovr.

Supported on:

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Centrify\CentrifyDC\Settings\NSSOverrides\Passwd
Value Namenss.overrides.enabled
Value TypeREG_DWORD
Enabled Value1
Disabled Value0
Enable policy:
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Centrify\CentrifyDC\Settings\NSSOverrides\Passwd
Value Namenss.passwd.override
Value TypeREG_SZ
Valuefile:/etc/centrifydc/passwd.ovr

--- FileVault ---

Encrypt contents with FileVault
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Centrify\CentrifyDC\Settings\NSSOverrides\Passwd
Value Namenss.passwd.override
Value TypeREG_SZ
Default Value0
True Value1
False Value0
Configure mobile account options



--- Size ---

Restrict size
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Centrify\CentrifyDC\Settings\NSSOverrides\Passwd
Value Namenss.passwd.override
Value TypeREG_SZ
Default Value0
True Value1
False Value0
fixed size (MB):

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Centrify\CentrifyDC\Settings\NSSOverrides\Passwd
Value Namenss.overrides.enabled
Value TypeREG_DWORD
Default Value250
Min Value0
Max Value
Home folder location:



Path:

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Centrify\CentrifyDC\Settings\NSSOverrides\Passwd
Value Namenss.overrides.enabled
Value TypeREG_DWORD
Default Value

centrifydc_settings.admx

Administrative Templates (Computers)

Administrative Templates (Users)