#7237 ipa-getkeytab man page should have more details about consequences of krb5 key renewal
Closed: fixed Opened by frenaud.

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1503022

Description of problem:
The 'ipa-getkeytab' tool is used to retrieve a kerberos keytab from the server.
The man page contains a warning that retrieving the keytab resets the secret
for the Kerberos principal and that this renders all other keytabs for that
principal invalid.
Some more details why resetting the key in a replicated environment might be
not the best idea should be added to the man page.
https://www.freeipa.org/page/V4/Keytab_Retrieval can be used as a reference.
Version-Release number of selected component (if applicable):
How reproducible:
Steps to Reproduce:
1.
2.
3.
Actual results:
Expected results:
Additional info:

Metadata Update from @frenaud:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1503022

Metadata Update from @frenaud:
- Custom field on_review adjusted to https://github.com/freeipa/freeipa/pull/1243
- Issue set to the milestone: None

Metadata Update from @frenaud:
- Issue assigned to frenaud

Metadata Update from @pvoborni:
- Issue priority set to: important
- Issue set to the milestone: FreeIPA 4.5.5

master:

  • 8b8437aa7342a79169913c886af4ac35f253aee2 ipa-getkeytab man page: add more details about the -r option

ipa-4-5:

  • 1f7ffb1ad0d4f5769494ae69a828788a5b90e6db ipa-getkeytab man page: add more details about the -r option

ipa-4-6:

  • e76ab3e8b08a4b4d08f05208117be38e383fa0a6 ipa-getkeytab man page: add more details about the -r option

Metadata Update from @stlaz:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Metadata