mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2025-02-25 18:55:28 -06:00
We have no visibility into whether an entry has a keytab or not so krbLastPwdChange is used as a rough guide. If this value exists during enrollment then it fails because the host is considered already joined. This was getting set when a OTP was added to a host that had already been enrolled (e.g. you enroll a host, unenroll it, set a OTP, then try to re-enroll). The second enrollment was failing because the enrollment plugin thought it was still enrolled becaused krbLastPwdChange was set. https://fedorahosted.org/freeipa/ticket/1357 |
||
---|---|---|
.. | ||
common | ||
ipa-enrollment | ||
ipa-lockout | ||
ipa-modrdn | ||
ipa-pwd-extop | ||
ipa-uuid | ||
ipa-version | ||
ipa-winsync | ||
Makefile.am | ||
README |