[20258] in Kerberos_V5_Development
Re: Adding password-expiration LAST_REQ message.
daemon@ATHENA.MIT.EDU (Benjamin Kaduk)
Tue Mar 2 18:34:56 2021
Date: Tue, 2 Mar 2021 15:34:40 -0800
From: Benjamin Kaduk <kaduk@mit.edu>
To: Ken Hornstein <kenh@cmf.nrl.navy.mil>
Message-ID: <20210302233440.GI21@kduck.mit.edu>
MIME-Version: 1.0
Content-Disposition: inline
In-Reply-To: <202103022257.122MvtfX030392@hedwig.cmf.nrl.navy.mil>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On Tue, Mar 02, 2021 at 05:59:15PM -0500, Ken Hornstein wrote:
> We have an old change to the MIT KDC that returns a password expiration
> time in the last-req field of the ticket. It also includes a KDC
> configuration entry to specify a time limit for sending the message
> (like if the password expiration is occuring within a week). The
> client support for this already exists in MIT Kerberos. Would this
> change (cleaned up and documented) be welcome to be submitted?
This would be a new "lr-type" value?
IIRC control over such registrations has not yet passed to IANA, so there
would probably not be procedural hoops to getting a new type...
-Ben
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev