[2477] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Password expiration via a preauth mechanism

daemon@ATHENA.MIT.EDU (Assar Westerlund)
Fri Aug 1 09:55:53 1997

To: Ken Hornstein <kenh@cmf.nrl.navy.mil>
Cc: joda@pdc.kth.se (Johan Danielsson), krbdev@MIT.EDU
From: Assar Westerlund <assar@sics.se>
Date: 01 Aug 1997 15:51:11 +0200
In-Reply-To: Ken Hornstein's message of Thu, 31 Jul 1997 12:06:54 -0400

Ken Hornstein <kenh@cmf.nrl.navy.mil> writes:
> Sam and I talked about this; he's referring to using the key_exp field
> in the KDC reply.  That should be a minimum of the password expiration
> time and the principal expiration time.  Currently in the MIT release,
> it's just the principal expiration time; in KerbNet, it's the password
> expiration time.

Just for comparison, Heimdal returns the minimum of the principal and
the password expiration time.

/assar

home help back first fref pref prev next nref lref last post