[30780] in Kerberos
Re: Long-running jobs with renewal of krb5 tickets and AFS tokens
daemon@ATHENA.MIT.EDU (Russ Allbery)
Sat Feb 28 23:44:55 2009
To: kerberos@mit.edu
In-Reply-To: <49AA11BA.3060509@rampaginggeek.com> (Jason Edgecombe's message
of "Sat\, 28 Feb 2009 23\:40\:26 -0500")
From: Russ Allbery <rra@stanford.edu>
Date: Sat, 28 Feb 2009 20:43:49 -0800
Message-ID: <87wsb97sze.fsf@windlord.stanford.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Jason Edgecombe <jason@rampaginggeek.com> writes:
> I guess setting things for renewable tickets longer than 7 days or
> running the jobs in local disk will be easiest.
>
> We have a 7 day normal/renewable lifetime. What length do other sites
> have?
Seven days here as well. That's also our limit on how long we let compute
jobs run on our normal timeshare systems. We're working on a batch
queuing system that will use separate cron instances.
> I might need use the job scheduler approach, but that's a pain. I would
> guess 10-20 people would want that ability. I ether need to modify our
> account maintenance processes or do it all manually.
>
> Has anyone automated the management of user.cron principals?
> unfortunately, I have had to tell people that they can't have an
> infinite ticket lifetime. :P
We've automated similar things here and there's some support for it in the
kadmin-remctl package. I'm hoping to clean that up substantially at some
point, but haven't had the time (and it's not in the top hundred on my
priority list at the moment).
--
Russ Allbery (rra@stanford.edu) <http://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos