I hav some questions regarding how data is organized when using the
>> LDAP KDB plugin for a realm. I hope this is the right place to ask.
querying a principal using kadmin, why attributes such as 'Last
[successful,failed] authentication' and 'Failed password attempts'
are
>> are
the
>> the
>> following:
>> ...
Last failed authentication: [never]
Failed password attempts: 0
...
>> Last failed authentication: [never]
>> Failed password attempts: 0
>> ...

> These attributes are updated only when the KDC is built with the
> "--with-kdc-kdb-update" option.

Which, unfortunately, doesn't seem to work since the DAL merge that
made the use of LDAP possible (e.g., RT tickets 5668, 5716 -- the
latter has a patch I haven't had a chance to evaluate).

This probably should be made a runtime option -- or at least, have the
configure-time option set a flag checked by code that's always
compiled in.