Hi If I set a kerberos principal for a user to expire on a given date using: ipa user-mod <user> --principal-expiration=DATE is it possible to later remove this expiration date rather than just set it to a time far in the future? Thanks Roderick Johnstone