Re: [Freeipa-users] howto modify krb principal attributes without kadmin.local

2012-05-18 Thread Simo Sorce
On Wed, 2012-05-16 at 15:08 -0700, Thomas Jackson wrote: On Tue, May 15, 2012 at 3:24 PM, Simo Sorce s...@redhat.com wrote: On Tue, 2012-05-15 at 14:21 -0700, Thomas Jackson wrote: So going through the documentation it's clearly laid out not to use kadmin

Re: [Freeipa-users] howto modify krb principal attributes without kadmin.local

2012-05-16 Thread Thomas Jackson
On Tue, May 15, 2012 at 3:24 PM, Simo Sorce s...@redhat.com wrote: On Tue, 2012-05-15 at 14:21 -0700, Thomas Jackson wrote: So going through the documentation it's clearly laid out not to use kadmin or kadmin.local when using freeipa. I have been unable to find how to replace this

Re: [Freeipa-users] howto modify krb principal attributes without kadmin.local

2012-05-16 Thread Simo Sorce
On Wed, 2012-05-16 at 18:15 -0400, Rob Crittenden wrote: Thomas Jackson wrote: kadmin.local: modprinc +requires_hwauth user modify_principal: User modification failed: Insufficient access while modifying user. What user's ticket do you have when trying to make this change? The error

Re: [Freeipa-users] howto modify krb principal attributes without kadmin.local

2012-05-15 Thread Simo Sorce
On Tue, 2012-05-15 at 14:21 -0700, Thomas Jackson wrote: So going through the documentation it's clearly laid out not to use kadmin or kadmin.local when using freeipa. I have been unable to find how to replace this functionality in the documentation. If I could use kadmin.local on my kdc I