Re: kerberos password change in master-slave environment

2004-03-24 Thread Mike Friedman
On Wed Mar 24 10:12:31 2004, Sam Hartman said: Subu Is there a more elegant solution, than say propagating Subu corporate wide kerberos database every 5 min or so ? First, this actually works fairly well. But the MIT client at least will try contacting the master (based on the

Re: kerberos password change in master-slave environment

2004-03-24 Thread Ken Hornstein
Unfortunately, PREAUTH_FAILED corresponds to the password being deemed incorrect, since we have requires_preauth on all user principals. Ever hear of the phrase, a little knowledge is dangerous? :-) KRB5_PREAUTH_FAILED is an internal client-side library error. KRB5KDC_ERR_PREAUTH_FAILED is

Re: kerberos password change in master-slave environment

2004-03-24 Thread Mike Friedman
On Wed Mar 24 16:05:49 2004, Ken Hornstein said: Unfortunately, PREAUTH_FAILED corresponds to the password being deemed incorrect, since we have requires_preauth on all user principals. Ever hear of the phrase, a little knowledge is dangerous? :-) I guess that makes me a Weapon of Mass