summaryrefslogtreecommitdiffstats
path: root/ipa-client/ipa-install/ipa-client-install
diff options
context:
space:
mode:
authorRob Crittenden <rcritten@redhat.com>2011-06-28 13:09:18 -0400
committerRob Crittenden <rcritten@redhat.com>2011-07-18 19:34:19 -0400
commita00b03831b6a7ccb87d58c92c1072c586889508e (patch)
tree8f473bf5de7a0a2dc56c3a93d3aeea4a35502bf5 /ipa-client/ipa-install/ipa-client-install
parente5a5c781f9c1152ff61cd21d649df99f465722c4 (diff)
downloadfreeipa-a00b03831b6a7ccb87d58c92c1072c586889508e.tar.gz
freeipa-a00b03831b6a7ccb87d58c92c1072c586889508e.tar.xz
freeipa-a00b03831b6a7ccb87d58c92c1072c586889508e.zip
Don't set krbLastPwdChange when setting a host OTP password.
We have no visibility into whether an entry has a keytab or not so krbLastPwdChange is used as a rough guide. If this value exists during enrollment then it fails because the host is considered already joined. This was getting set when a OTP was added to a host that had already been enrolled (e.g. you enroll a host, unenroll it, set a OTP, then try to re-enroll). The second enrollment was failing because the enrollment plugin thought it was still enrolled becaused krbLastPwdChange was set. https://fedorahosted.org/freeipa/ticket/1357
Diffstat (limited to 'ipa-client/ipa-install/ipa-client-install')
0 files changed, 0 insertions, 0 deletions