RE: cpw ignoring password policies

2020-08-14 Thread Dario García Díaz-Miguel
@mit.edu Asunto: RE: cpw ignoring password policies Hi Greg, Thank you so much for your Support and quick replies, really appreciated. > That's true. The kadmin server code deliberately only checks the minimum > life if a principal is changing its own password. Indeed. It makes sens

RE: cpw ignoring password policies

2020-08-14 Thread Dario García Díaz-Miguel
nal- De: Greg Hudson [mailto:ghud...@mit.edu] Enviado el: jueves, 13 de agosto de 2020 17:36 Para: Dario García Díaz-Miguel ; kerberos@mit.edu Asunto: Re: cpw ignoring password policies On 8/13/20 1:51 AM, Dario García Díaz-Miguel wrote: > I can change all the time the password of the princi

Re: cpw ignoring password policies

2020-08-13 Thread Greg Hudson
On 8/13/20 1:51 AM, Dario García Díaz-Miguel wrote: > I can change all the time the password of the principal with that policy > applied despite the minimum password life described. That's true. The kadmin server code deliberately only checks the minimum life if a principal is changing its own p

RE: cpw ignoring password policies

2020-08-13 Thread Dario García Díaz-Miguel
ewton, 11 28760, Tres Cantos, Madrid España +34 918 07 21 00 +34 918 07 21 99 www.gmv.com -Mensaje original- De: Greg Hudson [mailto:ghud...@mit.edu] Enviado el: miércoles, 12 de agosto de 2020 17:52 Para: Dario García Díaz-Miguel ; kerberos@mit.edu Asunto: Re: cpw ignoring password

Re: cpw ignoring password policies

2020-08-12 Thread Greg Hudson
On 8/12/20 5:39 AM, Dario García Díaz-Miguel wrote: > kadmin -k -t $KEYTABLOCATION -p $SERVICEPRINCIPAL -q "cpw $PRINCIPAL -pw > $PASSWORD" > > What we found is that this command ignores the password policy assigned to > the principal, including all the complexity rules and history options. No

cpw ignoring password policies

2020-08-12 Thread Dario García Díaz-Miguel
Hi there, I'm afraid we need some help from you. We are trying to integrate a Kerberized OpenLDAP environment with a LDAP user friendly management interface web application (LAM). This web application allows to use some custom scripts since the modules included by default are not suitable for