Project review: policy refcount elimination

Greg Hudson ghudson at MIT.EDU
Wed Jan 9 01:31:31 EST 2013

On 01/08/2013 08:14 PM, Nico Williams wrote:
> Could you make the kadmin/kadmin.local getprinc command fetch the
> princ's policy and display dangling policies?  (e.g., "Policy: foo*"
> or "Policy: foo [non-existent]")

That's a good idea.  I already have addprinc and modprinc warning (in
the kadmin client code) if you specify a policy which doesn't exist;
it's easy enough to make getprinc annotate nonexistent policy names.

More information about the krbdev mailing list