[2477] in Kerberos_V5_Development
Re: Password expiration via a preauth mechanism
daemon@ATHENA.MIT.EDU (Assar Westerlund)
Fri Aug 1 09:55:53 1997
To: Ken Hornstein <kenh@cmf.nrl.navy.mil>
Cc: joda@pdc.kth.se (Johan Danielsson), krbdev@MIT.EDU
From: Assar Westerlund <assar@sics.se>
Date: 01 Aug 1997 15:51:11 +0200
In-Reply-To: Ken Hornstein's message of Thu, 31 Jul 1997 12:06:54 -0400
Ken Hornstein <kenh@cmf.nrl.navy.mil> writes:
> Sam and I talked about this; he's referring to using the key_exp field
> in the KDC reply. That should be a minimum of the password expiration
> time and the principal expiration time. Currently in the MIT release,
> it's just the principal expiration time; in KerbNet, it's the password
> expiration time.
Just for comparison, Heimdal returns the minimum of the principal and
the password expiration time.
/assar