.Xr kpasswd 1 )
.
.Pp
-This daemon should only be run on ther master server, and not on any
+This daemon should only be run on the master server, and not on any
slaves.
.Pp
Principals are always allowed to change their own password and list
.Fl p Ar port ,
.Fl -ports= Ns Ar port
.Xc
-ports to listen to. By default, if run as a daemon, it listen to ports
+ports to listen to. By default, if run as a daemon, it listens to ports
749, and 751 (if Kerberos 4 support is built and enabled), but you can
add any number of ports with this option. The port string is a
whitespace separated list of port specifications, with the special
.Sh DESCRIPTION
.Nm
serves requests for tickets. When it starts, it first checks the flags
-passed, any options that are not specified with a command line flag is
+passed, any options that are not specified with a command line flag are
taken from a config file, or from a default compiled-in value.
.Pp
Options supported:
Turn off the requirement for pre-autentication in the initial AS-REQ
for all principals. The use of pre-authentication makes it more
difficult to do offline password attacks. You might want to turn it
-off if you have clients that doesn't do pre-authentication. Since the
-version 4 protocol doesn't support any pre-authentication, so serving
+off if you have clients that don't support pre-authentication. Since the
+version 4 protocol doesn't support any pre-authentication, serving
version 4 clients is just about the same as not requiring
pre-athentication. The default is to require
pre-authentication. Adding the require-preauth per principal is a more
is desired, or the automatic detection fails, this option might be used.
.El
.Pp
-All activities , are logged to one or more destinations, see
+All activities are logged to one or more destinations, see
.Xr krb5.conf 5 ,
and
.Xr krb5_openlog 3 .
section.
All the command-line options can preferably be added in the
configuration file. The only difference is the pre-authentication flag,
-that has to be specified as:
+which has to be specified as:
.Pp
.Dl require-preauth = no
.Pp
.Fl k Ar kspec ,
.Fl -keytab= Ns Ar kspec
.Xc
-keytab to get authentication key from
+Keytab to get authentication key from
.It Xo
.Fl r Ar realm ,
.Fl -realm= Ns Ar realm
.Xc
-default realm
+Default realm
.It Xo
.Fl p Ar string ,
.Fl -port= Ns Ar string
.Xc
-port to listen on (default service kpasswd - 464).
+Port to listen on (default service kpasswd - 464).
.El
.Sh DIAGNOSTICS
If an error occurs, the error message is returned to the user and/or