diff options
Diffstat (limited to 'src')
| -rw-r--r-- | src/kadmin/cli/kadmin.M | 5 | ||||
| -rw-r--r-- | src/plugins/kdb/ldap/libkdb_ldap/lockout.c | 2 |
2 files changed, 4 insertions, 3 deletions
diff --git a/src/kadmin/cli/kadmin.M b/src/kadmin/cli/kadmin.M index 9599bbf89..b05007a53 100644 --- a/src/kadmin/cli/kadmin.M +++ b/src/kadmin/cli/kadmin.M @@ -726,12 +726,13 @@ principals which require preauthentication. sets the allowable time between authentication failures. If an authentication failure happens after \fIfailuretime\fP has elapsed since the previous failure, the number of authentication failures is -reset to 1. +reset to 1. A failure count interval of 0 means forever. .TP \fB\-lockoutduration\fP \fIlockouttime\fP sets the duration for which the principal is locked from authenticating if too many authentication failures occur without the -specified failure count interval elapsing. +specified failure count interval elapsing. A duration of 0 means +forever. .sp .nf .TP diff --git a/src/plugins/kdb/ldap/libkdb_ldap/lockout.c b/src/plugins/kdb/ldap/libkdb_ldap/lockout.c index 36505f832..83d79e098 100644 --- a/src/plugins/kdb/ldap/libkdb_ldap/lockout.c +++ b/src/plugins/kdb/ldap/libkdb_ldap/lockout.c @@ -127,7 +127,7 @@ krb5_ldap_lockout_check_policy(krb5_context context, code = lookup_lockout_policy(context, entry, &max_fail, &failcnt_interval, &lockout_duration); - if (code != 0 || failcnt_interval == 0) + if (code != 0) return code; if (locked_check_p(context, stamp, max_fail, lockout_duration, entry)) |
