[37307] in Kerberos

home help back first fref pref prev next nref lref last post

Account unlocking and kadmin

daemon@ATHENA.MIT.EDU (John Devitofranceschi)
Sat Nov 7 12:09:26 2015

From: John Devitofranceschi <foonon@gmail.com>
Message-Id: <68483060-09A3-4560-99DE-6ACC6B9EB99D@gmail.com>
Date: Sat, 7 Nov 2015 12:00:53 -0500
To: kerberos@mit.edu
Mime-Version: 1.0 (Mac OS X Mail 9.1 \(3096.5\))
Content-Type: text/plain; charset="utf-8"
Errors-To: kerberos-bounces@mit.edu
Content-Transfer-Encoding: 8bit

Might it be the case that administrative account unlocking using kadmin (modprinc -unlock princname) will fail in some cases if the version of kadmin is not sufficiently modern?

For example, kadmin from 1.8.2 can be used to a unlock a principal on a 1.13.2 master, but not when the principal is locked on one of the slaves (when propagating from the master).

When a 1.13.2 kadmin is used, "modprinc -unlockā€ works for the master and the slaves.


jd
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos


home help back first fref pref prev next nref lref last post