[2213] in Kerberos
Re: stupid question regarding expired tickets in ticket cache
daemon@ATHENA.MIT.EDU (John Gardiner Myers)
Wed Sep 23 02:05:33 1992
Date: Tue, 22 Sep 1992 16:30:07 -0400
From: John Gardiner Myers <jgm+@cmu.edu>
To: kerberos@shelby.Stanford.EDU
louie@NI.UMD.EDU ("Louis A. Mamakos") writes:
> So I start tracing with the debugger, and what I find is that when the
> ticket cache is being searched for a ticket (given service name,
> instance and realm) in src/lib/krb/get_cred.c, there is no check for
> an expired ticket, and the expired ticket is returned with no attempt
> made to acquire a new ticket.
This appears to me to be a botch, but the implementors of the MIT
Kerberos library were probably just keeping things simple.
You can get patches to the MIT Kerberos library to support long ticket
lifetimes from export.acs.mit.edu in pub/kerberos.lifetime.patch
--
_.John G. Myers Internet: jgm+@CMU.EDU
LoseNet: ...!seismo!ihnp4!wiscvm.wisc.edu!give!up