> On Jun 30, 2015, at 12:56 PM, Greg Hudson <ghud...@mit.edu> wrote: > > On 06/27/2015 02:18 AM, John Devitofranceschi wrote: >> It seems that the 1.8.2 dump file claims to be ipropx, but it still only has >> the old-style policy records and that makes the 1.13.2 kpropd’s resync fail >> when kdb5_util is loading the kdb. > > It looks like we messed up when adding the 1.11 policy extensions, and > did not preserve iprop dump format compatibility. I have filed an issue > here: > > http://krbdev.mit.edu/rt/Ticket/Display.html?id=8213 > >> Are there any other possible work-arounds that don’t involve recompiling? > > I don't believe so. We can retroactively add compatibility with > pre-1.11 iprop dump files, but that would require recompiling (or > upgrading to some future version).
Okay, I’ll just continue to use my kdb5_util wrapper on our upgraded slaves until our master is upgraded and then revert to the unwrapped kdb5_util binary everywhere. Thanks for the info. jd ________________________________________________ Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos