[2099] in Kerberos_V5_Development
Re: Handling password expiration gracefully
daemon@ATHENA.MIT.EDU (Christopher Provenzano)
Tue Dec 10 00:32:20 1996
Reply-To: proven@cygnus.com
To: "Barry Jaspan" <bjaspan@MIT.EDU>
Cc: kenh@cmf.nrl.navy.mil, krbdev@MIT.EDU
In-Reply-To: Your message of "Mon, 09 Dec 1996 12:12:00 EST."
<9612091712.AA02877@DUN-DUN-NOODLES.MIT.EDU>
Date: Tue, 10 Dec 1996 00:26:16 -0500
From: Christopher Provenzano <proven@proven.org>
>
> An implementation that uses the kadm5 api is clearly (to me) the right
> way to start, because that api already exists and is easy to use.
> OV's login program did what you describe, with the following
> properties:
>
Maybe I'm missing something obvious, but doesn't this require login to talk
to the kadmind? Doesn't this defeat the purpose of having multiple slave kdcs?
CAP