A proposal for how to set msDS-KeyVersionNumber

Andrew Bartlett abartlet at samba.org
Mon Jun 7 05:13:24 MDT 2010


Attached is a proposal for how to set msDS-KeyVersionNumber

The idea is that if the knvo is incorrect in an upgraded DB, which may
cause trouble for unix clients joined to a Samba domain (but not Samba3,
or windows), that we want to manually set the knvo.

If this is too intrusive, then I suggest we just omit 'fixing' this, as
only a very small subset of our clients actually care about this value.

(I've have no complaints since I changed how we calculate this value 3
months ago). 

(untested, intended to be used with a future upgradeprovision)

Any comments?

Andrew Bartlett
-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org
Samba Developer, Cisco Inc.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-s4-dsdb-Allow-with-relax-the-setting-of-msDS-KeyVers.patch
Type: text/x-patch
Size: 3614 bytes
Desc: not available
URL: <http://lists.samba.org/pipermail/samba-technical/attachments/20100607/7db45ac1/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 190 bytes
Desc: This is a digitally signed message part
URL: <http://lists.samba.org/pipermail/samba-technical/attachments/20100607/7db45ac1/attachment.pgp>


More information about the samba-technical mailing list