freeipa/daemons/ipa-slapi-plugins
Rob Crittenden a00b03831b Don't set krbLastPwdChange when setting a host OTP password.
We have no visibility into whether an entry has a keytab or not so
krbLastPwdChange is used as a rough guide.

If this value exists during enrollment then it fails because the host
is considered already joined. This was getting set when a OTP was
added to a host that had already been enrolled (e.g. you enroll a host,
unenroll it, set a OTP, then try to re-enroll). The second enrollment
was failing because the enrollment plugin thought it was still
enrolled becaused krbLastPwdChange was set.

https://fedorahosted.org/freeipa/ticket/1357
2011-07-18 19:34:19 -04:00
..
common Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
ipa-enrollment Fix issues found by Coverity. 2011-05-09 16:23:40 -04:00
ipa-lockout Update kerberos password policy values on LDAP binds. 2011-01-21 13:59:24 -05:00
ipa-modrdn Unchecked return values in SLAPI plugins 2011-01-14 14:20:57 -05:00
ipa-pwd-extop Don't set krbLastPwdChange when setting a host OTP password. 2011-07-18 19:34:19 -04:00
ipa-uuid Fix issues found by Coverity. 2011-05-09 16:23:40 -04:00
ipa-version Disable replication version plugin by default. 2011-02-10 13:54:39 -05:00
ipa-winsync memory leak in ipa_winsync_get_new_ds_user_dn_cb 2011-06-28 00:11:04 -04:00
Makefile.am Update kerberos password policy values on LDAP binds. 2011-01-21 13:59:24 -05:00
README Mass tree reorganization for IPAv2. To view previous history of files use: 2009-02-03 15:27:14 -05:00