account lockout with ldap backend

Greg Hudson ghudson at MIT.EDU
Sun Nov 17 12:42:02 EST 2013

On 11/16/2013 03:26 PM, Paul B. Henson wrote:
> Could somebody please verify whether failures are replicated when using
> the ldap backend?

If your particular LDAP server is set up to replicate them, then yes.

> If so, it would be nice if the documentation were
> updated to reflect that.

The documentation refers to the Kerberos replication mechanisms (kprop
and iprop).  I will look for a way to clarify that the disclaimer
doesn't apply to replication which happens underneath the covers of the KDB.

More information about the Kerberos mailing list