[2211] in Kerberos

home help back first fref pref prev next nref lref last post

Re: stupid question regarding expired tickets in ticket cache

daemon@ATHENA.MIT.EDU (jon@MIT.EDU)
Tue Sep 22 18:28:49 1992

From: jon@MIT.EDU
To: "Louis A. Mamakos" <louie@ni.umd.edu>
Cc: kerberos@Athena.MIT.EDU
In-Reply-To: Your message of Tue, 22 Sep 92 11:00:27 -0400.
Date: Tue, 22 Sep 92 17:58:11 BST


Without going into the details I think you're probably right.  You
could fix up the library to do what you're suggesting and that would
be fine.  I suspect that nobody much runs into this because most
people's TGT expires at the same time as their service tickets.  The
only service tickets that last for a very short time are sensitive
apps (like the admin and passwd clients) and they usually get their
own initial tickets.

Also people are usually content to nuke their ticket cache's and
re-authenticate to the world.  Athena has an alias called "renew"
which gets a new TGT (after prompting for your password), gets tickets
and authenticates to each AFS cell and NFS server you're using and
deals with Zephyr.

You could also change the app (zephyr in this case) to request max
lifetime tickets (i.e. be bound by the TGT).  I surprised this isn't
automatically happening.

		-- Jon

home help back first fref pref prev next nref lref last post