Re: KDC model and atomicity

Nico Williams <[email protected]> Mon, 25 Jun 2012 11:21:04 -0500
Newsgroups gmane.ietf.krb-wg
Message-ID <CAK3OfOj1HvUMyD-7mC_+oasCW+V01mxMPQOVTwmrxmM65pN7tw@mail.gmail.com>
On Mon, Jun 25, 2012 at 10:41 AM, Jeffrey Hutzelman <[email protected]> wrote:
> Thus, I would not object to dropping them entirely.

I'd rather have at least an attribute by which to force unlock.
Otherwise we'll not be able to have a standard administration client
that can take care of this very important task of unlocking users
(which, of course, can only happen if the KDC implementation supports
N-strikes and, for whatever silly reason, has it enabled).

But I agree with you that we do not want a single attribute with
vaguely-defined semantics.  If we can't get consensus at all then by
all means, let's drop the feature.

Nico
--
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg