Re: [Freeipa-devel] [PATCH] 810 fix re-enrolling a host with a OTP

2011-07-19 Thread Rob Crittenden
Martin Kosek wrote: On Fri, 2011-07-01 at 11:40 -0400, Rob Crittenden wrote: Rob Crittenden wrote: Rob Crittenden wrote: Don't set krbLastPwdChange when setting a host OTP password. We have no visibility into whether an entry has a keytab or not so krbLastPwdChange is used as a rough guide.

Re: [Freeipa-devel] [PATCH] 810 fix re-enrolling a host with a OTP

2011-07-19 Thread Martin Kosek
On Fri, 2011-07-01 at 11:40 -0400, Rob Crittenden wrote: > Rob Crittenden wrote: > > Rob Crittenden wrote: > >> Don't set krbLastPwdChange when setting a host OTP password. > >> > >> We have no visibility into whether an entry has a keytab or not so > >> krbLastPwdChange is used as a rough guide. >

Re: [Freeipa-devel] [PATCH] 810 fix re-enrolling a host with a OTP

2011-07-01 Thread Rob Crittenden
Rob Crittenden wrote: Rob Crittenden wrote: Don't set krbLastPwdChange when setting a host OTP password. We have no visibility into whether an entry has a keytab or not so krbLastPwdChange is used as a rough guide. If this value exists during enrollment then it fails because the host is consid

Re: [Freeipa-devel] [PATCH] 810 fix re-enrolling a host with a OTP

2011-06-30 Thread Rob Crittenden
Rob Crittenden wrote: Don't set krbLastPwdChange when setting a host OTP password. We have no visibility into whether an entry has a keytab or not so krbLastPwdChange is used as a rough guide. If this value exists during enrollment then it fails because the host is considered already joined. Th

[Freeipa-devel] [PATCH] 810 fix re-enrolling a host with a OTP

2011-06-28 Thread Rob Crittenden
Don't set krbLastPwdChange when setting a host OTP password. We have no visibility into whether an entry has a keytab or not so krbLastPwdChange is used as a rough guide. If this value exists during enrollment then it fails because the host is considered already joined. This was getting set w