[18977] in Kerberos_V5_Development
Re: kadmind: password history interaction with keepold
daemon@ATHENA.MIT.EDU (Greg Hudson)
Fri Aug 15 09:53:03 2014
Message-ID: <53EE10B1.8050803@mit.edu>
Date: Fri, 15 Aug 2014 09:52:49 -0400
From: Greg Hudson <ghudson@mit.edu>
MIME-Version: 1.0
To: Tomas Kuthan <tomas.kuthan@oracle.com>, krbdev@mit.edu
In-Reply-To: <53CFAC77.70001@oracle.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On 07/23/2014 08:37 AM, Tomas Kuthan wrote:
> I have ran into a corner case and I am not really sure if the behavior
> in the back-end agnostic code is correct with respect to use of -keepold
> option with principals with password history.
> In my opinion, with -keepold, old keys are retained in password history
> for too long.
Sorry, I missed this message somehow. I agree completely; only the most
recent kvno should be stored in the history record.
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev