[Freeipa-devel] [PATCH] #412 Make always use of special salt type

Simo Sorce ssorce at redhat.com
Wed Oct 27 21:12:39 UTC 2010


By using the special salt type and generating a random salt we can
rename user's principal name without invalidating their password.

This works only if pre-authentication is required, but that's how we
configure our server anyway.

This patch does not disallow "normal" salts, but if used they will
prevent renames from working correctly.
By default special is used.

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-simo-0001-pwd-plugin-Always-use-a-special-salt-by-default.patch
Type: text/x-patch
Size: 4704 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20101027/ee3e016c/attachment.bin>


More information about the Freeipa-devel mailing list