On Mon, Dec 02, 2013 at 12:52:31PM +1100, Brian May wrote:
> On 2 December 2013 12:31, Russ Allbery <r...@debian.org> wrote:
> 
> > It's never been clear to me why you would ever care to have a known master
> > key password, as opposed to just using kstash --random-key.  The only
> > reason I can think of would be to recover the Kerberos KDC database when
> > you have a copy of the database but not the master key, but I'm not sure
> > why you would be in that state.  It's just as easy to back up the master
> > key file along with the database.
> >
> 
> Yes, agreed. It seemed a good idea at the time...
> 
> Maybe --random-key wasn't available when I initially wrote that stuff. Or
> maybe I just didn't know about it.

I can't think of a good reason either; I figured that since the question
was there, there would probably be a reason for it. Perhaps it's time
to downgrade the priority of the password question to "low" ?

Cheers,

Jelmer

Attachment: signature.asc
Description: Digital signature

Reply via email to