Re: [Freeipa-devel] [PATCH] 586 kerberos password policy

2010-11-01 Thread Adam Young
On 10/29/2010 04:39 PM, Rob Crittenden wrote: Simo Sorce wrote: On Mon, 25 Oct 2010 18:05:46 -0400 Rob Crittenden wrote: Use kerberos password policy. This lets the KDC count password failures and can lock out accounts for a period of time. This only works for KDC>= 1.8. There currently is

Re: [Freeipa-devel] [PATCH] 586 kerberos password policy

2010-10-29 Thread Rob Crittenden
Simo Sorce wrote: On Mon, 25 Oct 2010 18:05:46 -0400 Rob Crittenden wrote: Use kerberos password policy. This lets the KDC count password failures and can lock out accounts for a period of time. This only works for KDC>= 1.8. There currently is no way to unlock a locked account across a repl

Re: [Freeipa-devel] [PATCH] 586 kerberos password policy

2010-10-28 Thread Simo Sorce
On Mon, 25 Oct 2010 18:05:46 -0400 Rob Crittenden wrote: > Use kerberos password policy. > > This lets the KDC count password failures and can lock out accounts > for a period of time. This only works for KDC >= 1.8. > > There currently is no way to unlock a locked account across a > replica. M