Request to change MIT Kerberos behavior when principal is expired, deleted or password changed

Nico Williams nico at cryptonector.com
Thu Mar 6 12:29:55 EST 2014


FWIW, Heimdal's TGS already does reject requests for clients whose
principals should exist int he local HDB but don't.  (Obviously this
can only be done when the client's realm is also a realm for which the
KDC has a database.)

Nico
--


More information about the Kerberos mailing list