"Edgecombe, Jason" <[email protected]> writes:

> I don't see how anyone can object to rejecting requests for expired or
> deleted principals. I understand that the password changing aspect could
> be more controversial.

> Could we at least add the "reject requests for expired/removed
> principals" part?

+1.  This seems like a much better default to me.

-- 
Russ Allbery ([email protected])              <http://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos

Reply via email to