[27696] in Kerberos
Re: confusion in ank.
daemon@ATHENA.MIT.EDU (Kevin Coffman)
Mon Apr 23 11:29:01 2007
Message-ID: <4d569c330704230827q5e37a841wcb8adffc8cbedeb@mail.gmail.com>
Date: Mon, 23 Apr 2007 11:27:22 -0400
From: "Kevin Coffman" <kwc@citi.umich.edu>
To: "Vipin Rathor" <v.rathor@gmail.com>
In-Reply-To: <33ab2aef0704230714i7667e209p66ed03fbad1937ba@mail.gmail.com>
MIME-Version: 1.0
Content-Disposition: inline
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
On 4/23/07, Vipin Rathor <v.rathor@gmail.com> wrote:
> hi all,
>
> >> My questions:
> >> 1. Is this an expected behavior?
> >> 2. Is this happening because of '-randkey'? (since not specifying
> -randkey
> >> gave proper Password expiration date.)
>
> >It probably is happening because of -randkey, although I think that's a
> >bug.
>
> If Russ thinks that it's a bug, can somebody please tell me that what should
> be the
> correct behavior? and Where can I get this(in RFC...I guess???)
I haven't looked at the code, but I think this is probably done on
purpose and is not a bug. When you create a keytab, you create a new
random key for the account. There is no password associated with that
key, and there is no longer a reason for a password expiration.
K.C.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos