Re: KDC model and atomicity
Nico Williams <[email protected]> Mon, 25 Jun 2012 11:21:04 -0500
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <CAK3OfOj1HvUMyD-7mC_+oasCW+V01mxMPQOVTwmrxmM65pN7tw@mail.gmail.com> |
On Mon, Jun 25, 2012 at 10:41 AM, Jeffrey Hutzelman <[email protected]> wrote: > Thus, I would not object to dropping them entirely. I'd rather have at least an attribute by which to force unlock. Otherwise we'll not be able to have a standard administration client that can take care of this very important task of unlocking users (which, of course, can only happen if the KDC implementation supports N-strikes and, for whatever silly reason, has it enabled). But I agree with you that we do not want a single attribute with vaguely-defined semantics. If we can't get consensus at all then by all means, let's drop the feature. Nico -- _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg