1 .TH "KPASSWD" "1" "January 06, 2012" "0.0.1" "MIT Kerberos"
3 kpasswd \- change a user's Kerberos password
5 .nr rst2man-indent-level 0
9 level \\n[rst2man-indent-level]
10 level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
17 .\" .rstReportMargin pre:
19 . nr rst2man-indent\\n[rst2man-indent-level] \\n[an-margin]
20 . nr rst2man-indent-level +1
21 .\" .rstReportMargin post:
25 .\" indent \\n[an-margin]
26 .\" old: \\n[rst2man-indent\\n[rst2man-indent-level]]
27 .nr rst2man-indent-level -1
28 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
29 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
31 .\" Man page generated from reStructeredText.
35 \fIkpasswd\fP [ \fIprincipal\fP ]
38 The \fIkpasswd\fP command is used to change a Kerberos principal\(aqs password.
39 \fIkpasswd\fP prompts for the current Kerberos password, which is used to obtain a
40 \fIchangepw\fP ticket from the KDC for the user\(aqs Kerberos realm.
41 If \fIkpasswd\fP successfully obtains the \fIchangepw\fP ticket, the user is prompted twice for
42 the new password, and the password is changed.
44 If the principal is governed by a policy that specifies the length and/or number of
45 character classes required in the new password, the new password must conform to the policy.
46 (The five character classes are lower case, upper case, numbers, punctuation, and all other characters.)
52 Change the password for the Kerberos principal principal.
53 Otherwise, \fIkpasswd\fP uses the principal name from an existing ccache if there is one;
54 if not, the principal is derived from the identity of the user invoking the \fIkpasswd\fP command.
58 \fIkpasswd\fP looks first for:
62 kpasswd_server = host:port
66 in the [\fIrealms\fP] section of the \fIkrb5.conf\fP file under the current realm.
67 If that is missing, \fIkpasswd\fP looks for the \fIadmin_server\fP entry, but substitutes 464 for the port.
73 \fIkpasswd\fP may not work with multi\-homed hosts running on the Solaris platform.
78 .\" Generated by docutils manpage writer.