> But the database can store a special > salt string for a principal's key, so you'd modify some (most?) > entries for users to have the salt string computed based on the old > realm name.
If anyone is thinking of going down this road, be aware that there are some crappy client implementations out there (* looks in the direction of WebCT Vista and coughs *) that don't handle a non-default salt correctly... John ________________________________________________ Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos