[31959] in Kerberos
Re: find inactive accounts
daemon@ATHENA.MIT.EDU (Ken Raeburn)
Wed Jan 20 09:48:11 2010
From: Ken Raeburn <raeburn@mit.edu>
To: John Hascall <john@iastate.edu>
In-Reply-To: <25591.1263996937@malison.ait.iastate.edu>
Message-Id: <F3742516-48CA-4BE2-A2E8-205B5BF28533@mit.edu>
Mime-Version: 1.0 (Apple Message framework v936)
Date: Wed, 20 Jan 2010 09:47:42 -0500
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
On Jan 20, 2010, at 09:15, John Hascall wrote:
> Ah yes, I'd forgotten that.
> so:
> 1a) I would use an incremental propagation technique.
The current iprop mechanism relies on full propagation in cases where
the slave has gotten too far behind. It's automatic, too, so both
modes need to support per-KDC info. (And for all I know, maybe in the
1.8 branch they do now.)
> and
> 1b) I'd bug the Kerb team to fix this :)
Go for it, but note the signature below... :-)
--
Ken Raeburn / raeburn@mit.edu / no longer at MIT Kerberos Consortium
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos