freeipa/daemons
Rob Crittenden a00b03831b Don't set krbLastPwdChange when setting a host OTP password.
We have no visibility into whether an entry has a keytab or not so
krbLastPwdChange is used as a rough guide.

If this value exists during enrollment then it fails because the host
is considered already joined. This was getting set when a OTP was
added to a host that had already been enrolled (e.g. you enroll a host,
unenroll it, set a OTP, then try to re-enroll). The second enrollment
was failing because the enrollment plugin thought it was still
enrolled becaused krbLastPwdChange was set.

https://fedorahosted.org/freeipa/ticket/1357
2011-07-18 19:34:19 -04:00
..
ipa-kpasswd Mozldap-specific code removed 2011-01-14 17:33:11 -05:00
ipa-slapi-plugins Don't set krbLastPwdChange when setting a host OTP password. 2011-07-18 19:34:19 -04:00
configure.ac Update kerberos password policy values on LDAP binds. 2011-01-21 13:59:24 -05:00
ipa-version.h.in Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
Makefile.am Stricter compilation flags 2010-11-22 16:01:35 -05:00