We're using 7.0, so I've been going by the 7.0 documentation. It has explicit differentiation between password management (expiration, complexity, warning) and password change. 7.0 Administration Guide - page 159 When authenticating against a generic LDAP server, such as IBM Secure Directory, the SA Series SSL VPN Appliance only supports authentication and allowing users to change their passwords. And Table 9, directly below, shows the exact same thing: password change is supported, nothing else is. Interesting to see that the section was rewritten between 6.5, 7.0, and 7.1.
... View more