On Tue, 2012-11-13 at 21:53 -0600, Anthony Messina wrote:
> 1. Using automatic login with the lightdm display manager, I have it
> run the 
> following script to remove any old Kerberos ccaches, then obtain a new
> ticket 
> on behalf of the user, and set the appropriate permissions and
> SELinux 
> context.  Note that in this case, I echo the password to kinit -- If
> I 
> exported a keytab, I would not be able to manually login with a known
> password 
> if there were a problem.

Just FYI, this is not strictly true, look at the -P, --password option
of ipa-getkeytab :-)


Simo Sorce * Red Hat, Inc * New York

Freeipa-users mailing list

Reply via email to