Don't try to convert a host's password into a keytab.

The migration plugin uses a pre-op function to automatically create kerberos credentials when binding using a password.

The problem is that we do a simple bind when doing password-base host enrollment. This was causing krbPasswordExpiration to be set which isn't what we want for hosts. They really shouldn't go through this code at all.

rob

Attachment: freeipa-468-enroll.patch
Description: application/mbox

_______________________________________________
Freeipa-devel mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/freeipa-devel

Reply via email to