changing password/keys but still being able to use the old ones

Greg Hudson ghudson at
Thu Dec 22 11:02:58 EST 2016

On 12/22/2016 09:15 AM, Sorin Manolache wrote:
> Therefore, at moment t_2, when the user makes a request to the http 
> server, his ticket that uses the kvno 2 keys cannot be validated by the 
> service that uses the keytab with the kvno 1 keys.

Yes, this is a known weakness of the current kadmin.  I think it was
first reported here:

It becomes a larger problem with clustered services.  We discussed some
possible resolutions in this thread on the krbdev list:

In terms of immediate resolution, the only option I know of is to use
Roland's admin system:

More information about the Kerberos mailing list