Pwpolicy Password Reset Issue with Local Items Keychain

moonan
New Contributor

Wondering if anyone else ran into this. We were using the following as a local policy to force a password reset when setting up a Mavericks system for a user:

pwpolicy -u username -setpolicy "newPasswordRequired=1"

This works fine under Mountain Lion, but not under Mavericks. It appears to work initially, but on subsequent logins the user will get popups to unlock the "Local Items" keychain which is still locked with the old password.

From what I can tell, the "Local Items" keychain only seems to exist on a system until an iCloud account is set up (or at least the iCloud keychain is turned on) at which point it is replaced with the "iCloud" keychain. The "Local Items" keychain doesn't exist under Mountain Lion.

Kinda feels like a bug, but I can't find reference to it anywhere...

Thanks!

0 REPLIES 0