[37496] in Kerberos

home help back first fref pref prev next nref lref last post

Re-authentication vs Renewal of credentials by a service and the

daemon@ATHENA.MIT.EDU (Todd Grayson)
Thu May 12 09:48:56 2016

MIME-Version: 1.0
From: Todd Grayson <tgrayson@cloudera.com>
Date: Thu, 12 May 2016 09:48:18 -0400
Message-ID: <CALNT6MU=T907q18a8O7J8Wi1uuZJC5zYSSJi8vBuPhzg4KxKRA@mail.gmail.com>
To: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Hello,

When a service re-authenticates to the KDC, effectively getting a new TGT,
are the service tickets related to previous instance of the TGT for that
service, no longer valid?

That is, does a service re-authenticating to a KDC, rather than renewing,
cause all the current related service tickets to no longer be valid and in
turn trigger all those clients holding the previous generation of tickets,
to re-request a service ticket at that point from the KDC?

Or is that service ticket durable, and will it survive replacement (not
renewal) of the underlying TGT?
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post