[27697] in Kerberos

home help back first fref pref prev next nref lref last post

Re: confusion in ank.

daemon@ATHENA.MIT.EDU (Nicolas Williams)
Mon Apr 23 11:54:23 2007

Date: Mon, 23 Apr 2007 10:52:36 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: Kevin Coffman <kwc@citi.umich.edu>
Message-ID: <20070423155235.GE12578@Sun.COM>
Mail-Followup-To: Kevin Coffman <kwc@citi.umich.edu>,
	Vipin Rathor <v.rathor@gmail.com>, kerberos@mit.edu
Mime-Version: 1.0
Content-Disposition: inline
In-Reply-To: <4d569c330704230827q5e37a841wcb8adffc8cbedeb@mail.gmail.com>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

On Mon, Apr 23, 2007 at 11:27:22AM -0400, Kevin Coffman wrote:
> I haven't looked at the code, but I think this is probably done on
> purpose and is not a bug.  When you create a keytab, you create a new
> random key for the account.  There is no password associated with that
> key, and there is no longer a reason for a password expiration.

Password quality policies certainly shouldn't apply to randomly-
generated keys, but that does not mean that there cannot be a key
expiration policy.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post