krb5-kdc: Cannot change passwords if password history is used
Tom Yu
tlyu at MIT.EDU
Wed Mar 7 11:33:08 EST 2012
Nico Williams <nico at cryptonector.com> writes:
> But there's no integrity protection for most of the KDB, so there's no
> way to know if the problem is corruption. That said, I agree with
> you: removing the required key == removing that part of the password
> history keyed with that key.
The keys that the KDC uses to encrypt long-term keys (and key
histories) in the KDB typically provide integrity protection. What
sort of corruption were you thinking of?
More information about the Kerberos
mailing list