[2309] in Kerberos

home help back first fref pref prev next nref lref last post

Aging of kerberos passwords...

daemon@ATHENA.MIT.EDU (Mike Busby)
Mon Oct 26 19:27:42 1992

From: mcb@mach.eng.hou.compaq.com (Mike Busby)
To: kerberos%athena.mit.edu@twisto.eng.hou.compaq.com
Date: Mon, 26 Oct 92 18:01:50 CST


Hilary Jones
(hilary@snll-arpagw.llnl.gov) writes:

> 
> We have modified Kerberos to use the key version number to handle this.
> All new accounts start with a key version number of zero.  Such an
> account is considered to have an expired password.  The user must run
> kpasswd to change his password before he can use the account.  We have
> also modified some of the other utilities to allow the administrator to
> zero the key version.
> 

I would be interested in hearing from anyone who has done something similar
to the above.  We are deploying kerberos V4 and would like to
be able to age and/or expire kerberos passwords.  Password aging is of
particular interest.  Any help would be appreciated.

Thanks,

-- 
Michael C. Busby - System Engineer, Sr.
----------------------------------------------------------------------
Compaq Computer Corporation        |  Internet: mcb@compaq.com        
P.O. Box 692000 m/s 050701         |  Uunet:    uunet!cpqhou!michaelb 
Houston, Texas, USA 77269-2000     |  Phone:    713-374-5638          
----------------------------------------------------------------------
"Armadillos....  Texas speed bumps."    Views/opinions are mine alone.

home help back first fref pref prev next nref lref last post