Re: [Freeipa-devel] [PATCH] #412 Make always use of special salt type

2010-10-28 Thread Rob Crittenden
Simo Sorce wrote: By using the special salt type and generating a random salt we can rename user's principal name without invalidating their password. This works only if pre-authentication is required, but that's how we configure our server anyway. This patch does not disallow normal salts,

Re: [Freeipa-devel] [PATCH] #412 Make always use of special salt type

2010-10-28 Thread Simo Sorce
On Thu, 28 Oct 2010 17:14:54 -0400 Rob Crittenden rcrit...@redhat.com wrote: Simo Sorce wrote: By using the special salt type and generating a random salt we can rename user's principal name without invalidating their password. This works only if pre-authentication is required, but

[Freeipa-devel] [PATCH] #412 Make always use of special salt type

2010-10-27 Thread Simo Sorce
By using the special salt type and generating a random salt we can rename user's principal name without invalidating their password. This works only if pre-authentication is required, but that's how we configure our server anyway. This patch does not disallow normal salts, but if used they will