Re: [Freeipa-users] Admin cannot retrieve keytab -- is that expected?

2017-04-17 Thread Jan Pazdziora
On Mon, Apr 17, 2017 at 04:49:59PM +0300, Alexander Bokovoy wrote: > On Mon, 17 Apr 2017, Jan Pazdziora wrote: > > > > Hello, > > > > on freeipa-server-4.4.4-1.fc25.x86_64, admin can generate and retrieve > > new keytab for a service but they cannot retrieve the existing keys > > with the -r opti

Re: [Freeipa-users] Admin cannot retrieve keytab -- is that expected?

2017-04-17 Thread Alexander Bokovoy
On Mon, 17 Apr 2017, Jan Pazdziora wrote: Hello, on freeipa-server-4.4.4-1.fc25.x86_64, admin can generate and retrieve new keytab for a service but they cannot retrieve the existing keys with the -r option. Is that expected? Yes. Access to existing keys is intentionally restricted. There are

[Freeipa-users] Admin cannot retrieve keytab -- is that expected?

2017-04-17 Thread Jan Pazdziora
Hello, on freeipa-server-4.4.4-1.fc25.x86_64, admin can generate and retrieve new keytab for a service but they cannot retrieve the existing keys with the -r option. Is that expected? # kdestroy -A # kinit admin Password for ad...@example.test: # ipa host-add test1.example.test --force