On Tue, 2012-11-13 at 21:53 -0600, Anthony Messina wrote: > 1. Using automatic login with the lightdm display manager, I have it > run the > following script to remove any old Kerberos ccaches, then obtain a new > ticket > on behalf of the user, and set the appropriate permissions and > SELinux > context. Note that in this case, I echo the password to kinit -- If > I > exported a keytab, I would not be able to manually login with a known > password > if there were a problem.
Just FYI, this is not strictly true, look at the -P, --password option of ipa-getkeytab :-) Simo. -- Simo Sorce * Red Hat, Inc * New York _______________________________________________ Freeipa-users mailing list [email protected] https://www.redhat.com/mailman/listinfo/freeipa-users
