Pavel Zuna wrote:
Re-post from ipa-and-samba-team-list.

This patch makes DS generate new Kerberos keys for eligible users upon a successful simple bind. We need this for password migration.


Some minor points:

- The comment block of ipa_pwd_pre_bind() doesn't match the code: it doesn't add krbPrincipalAux or set the principal name.
- It probably shouldn't use log level SLAPI_LOG_FATAL


