[27696] in Kerberos

home help back first fref pref prev next nref lref last post

Re: confusion in ank.

daemon@ATHENA.MIT.EDU (Kevin Coffman)
Mon Apr 23 11:29:01 2007

Message-ID: <4d569c330704230827q5e37a841wcb8adffc8cbedeb@mail.gmail.com>
Date: Mon, 23 Apr 2007 11:27:22 -0400
From: "Kevin Coffman" <kwc@citi.umich.edu>
To: "Vipin Rathor" <v.rathor@gmail.com>
In-Reply-To: <33ab2aef0704230714i7667e209p66ed03fbad1937ba@mail.gmail.com>
MIME-Version: 1.0
Content-Disposition: inline
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

On 4/23/07, Vipin Rathor <v.rathor@gmail.com> wrote:
> hi all,
>
> >> My questions:
> >> 1. Is this an expected behavior?
> >> 2. Is this happening because of '-randkey'? (since not specifying
> -randkey
> >>  gave proper Password expiration date.)
>
> >It probably is happening because of -randkey, although I think that's a
> >bug.
>
> If Russ thinks that it's a bug, can somebody please tell me that what should
> be the
> correct behavior? and Where can I get this(in RFC...I guess???)

I haven't looked at the code, but I think this is probably done on
purpose and is not a bug.  When you create a keytab, you create a new
random key for the account.  There is no password associated with that
key, and there is no longer a reason for a password expiration.

K.C.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post