Key history with LDAP backend?

2014-11-04 Thread Andreas Ntaflos
Hi, I see that the "-history" option for "add_policy" (in kadmin) is not supported when using the LDAP backend for Kerberos [1]. Is there *any* other way to ensure a user doesn't use one of his previous four keys when changing passwords and the Kerberos database is in LDAP? I ask because this is

Re: Key history with LDAP backend?

2014-11-04 Thread Greg Hudson
On 11/04/2014 12:54 PM, Andreas Ntaflos wrote: > Hi, > > I see that the "-history" option for "add_policy" (in kadmin) is not > supported when using the LDAP backend for Kerberos [1]. We expect to have this implemented this for 1.14 (see https://github.com/krb5/krb5/pull/132 ) but for now that is