Re: Password has expired while getting initial ticket during replication

2019-12-03 Thread Stephen Carville (Kerberos List)
On 12/2/19 12:58 PM, Greg Hudson wrote: > Lereta Email Checkpoint: External email. Please make sure you trust this > source before clicking links or opening attachments. > > ** > > On 12/2/19 3:23 PM, Stephen Carville (Kerberos

Re: Password has expired while getting initial ticket during replication

2019-12-02 Thread Greg Hudson
On 12/2/19 3:23 PM, Stephen Carville (Kerberos List) wrote: > It seems that when I add a key to the keytab file the password > expiration date for that host is set to somewhen in 1903. I've never > noticed that behavior before and it only seems to happen to KDCs. I would guess that these princi

Re: Password has expired while getting initial ticket during replication

2019-12-02 Thread Stephen Carville (Kerberos List)
On 12/2/19 11:22 AM, Greg Hudson wrote: > On 12/2/19 12:02 PM, Stephen Carville (Kerberos List) wrote: >> /usr/sbin/kprop: Password has expired while getting initial ticket > > At startup, kprop retrieves a TGT for the client principal > host/@REALM using the keytab. You can simulate this with >

Re: Password has expired while getting initial ticket during replication

2019-12-02 Thread Greg Hudson
On 12/2/19 12:02 PM, Stephen Carville (Kerberos List) wrote: > /usr/sbin/kprop: Password has expired while getting initial ticket At startup, kprop retrieves a TGT for the client principal host/@REALM using the keytab. You can simulate this with "kinit -k host/@REALM". It sounds like this client