question about KRB5_KDB_DISALLOW_ALL_TIX attribute

Nicolas Williams Nicolas.Williams at ubsw.com
Thu Feb 7 16:57:18 EST 2002


The kadmin protocol doesn't have a search function AFAICT.

And the KDB is indexed only by name, so you can't search it
without traversing it entirely anyways.

Nico

On Thu, Feb 07, 2002 at 01:38:53PM -0800, Dave Steiner wrote:
> We've been running Kerberos here at the University for a number of
> years.  We've made a few changes to the code over that time and one of
> the changes is that we don't lockout principals after N failed
> attempts.
> 
> We are now going to start using the lockout code that's in the kdc but
> we'd like some way to identify the people who are locked out (so we
> can either contact them, semi-automate a +allow_tix, etc). 
> Unfortunately, I haven't found any easy way of getting a list of
> locked out people except to do a dump of the database and check the
> attributes of each entry in the dump.
> 
> Does anyone have an easier way to get this information or am I stuck
> with the dump method?
> 
> thanks,
> -ds
> _______________________________________________
> Kerberos mailing list
> Kerberos at mit.edu
> http://mailman.mit.edu/mailman/listinfo/kerberos
-- 
-DISCLAIMER: an automatically appended disclaimer may follow. By posting-
-to a public e-mail mailing list I hereby grant permission to distribute-
-and copy this message.-

Visit our website at http://www.ubswarburg.com

This message contains confidential information and is intended only 
for the individual named.  If you are not the named addressee you 
should not disseminate, distribute or copy this e-mail.  Please 
notify the sender immediately by e-mail if you have received this 
e-mail by mistake and delete this e-mail from your system.

E-mail transmission cannot be guaranteed to be secure or error-free 
as information could be intercepted, corrupted, lost, destroyed, 
arrive late or incomplete, or contain viruses.  The sender therefore 
does not accept liability for any errors or omissions in the contents 
of this message which arise as a result of e-mail transmission.  If 
verification is required please request a hard-copy version.  This 
message is provided for informational purposes and should not be 
construed as a solicitation or offer to buy or sell any securities or 
related financial instruments.




More information about the Kerberos mailing list