[30416] in Kerberos

home help back first fref pref prev next nref lref last post

Destroy expired tickets?

daemon@ATHENA.MIT.EDU (Stefan Monnier)
Thu Nov 6 09:10:55 2008

To: kerberos@mit.edu
From: Stefan Monnier <monnier@iro.umontreal.ca>
Date: Wed, 05 Nov 2008 21:16:41 -0500
Message-ID: <jwvmygdsiwn.fsf-monnier+gmane.comp.encryption.kerberos.general@gnu.org>
Mime-Version: 1.0
X-Complaints-To: usenet@ger.gmane.org
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

How can I destroy expired tickets?

They're useless at best, and in some cases they're positively harmful
(their presence prompts `ssh' to contact the KDC to try and delegate
credentials, which is a waste if the tickets are expired, and is really
annoying when the KDC times out because it's behind a firewall).

But I couldn't find any command that would destroy only expired tickets.
Any idea what I should use?  I guess I could try and parse the date&time
in "klist", but it'd be a pain in the rear and blatantly brittle.

This is on a Debian GNU/Linux system, in case it matters,


        Stefan

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post