pam.password.change.required.mesg
This configuration parameter specifies the message displayed if the user enters the correct password, but the password must be changed immediately.
For example:
pam.password.change.required.mesg: \ You are required to change your password immediately