Re: [Freeipa-users] Kerberos Password change limitation while behind a NAT

2010-09-30 Thread Marc Schlinger
Le 30/09/2010 18:30, Simo Sorce a écrit : You can use ldappasswd too, either with GSSAPI auth or eventually even with plaintext auth (require using SSL) in that case though you will neeed to know the user DN. Simo. So if a user logs in when his password is expired, will pam_ldap in the

Re: [Freeipa-users] Kerberos Password change limitation while behind a NAT

2010-09-30 Thread Rob Crittenden
Marc Schlinger wrote: Le 30/09/2010 18:30, Simo Sorce a écrit : You can use ldappasswd too, either with GSSAPI auth or eventually even with plaintext auth (require using SSL) in that case though you will neeed to know the user DN. Simo. So if a user logs in when his password is expired,

[Freeipa-users] Supporting multiple seperate kerberos providers

2010-09-30 Thread Dennis Gilmore
Hi All, One thing that some folks in Fedora are evaluating is to integrate freeipa with fas, this would enable services like koji to gain kerberos auth, as well as git etc. It could also be enabled on fedorahosted etc. but it brings to light a deficiency in krb5. while you can define multiple