[22745] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Renewable Tickets

daemon@ATHENA.MIT.EDU (Ken Raeburn)
Mon Oct 25 15:28:41 2004

In-Reply-To: <20041025190220.GO26380@usc.edu>
Mime-Version: 1.0 (Apple Message framework v619)
Content-Type: text/plain; charset=US-ASCII; format=flowed
Message-Id: <32BF440E-26BB-11D9-B5AB-000A95909EE2@mit.edu>
Content-Transfer-Encoding: 7bit
From: Ken Raeburn <raeburn@mit.edu>
Date: Mon, 25 Oct 2004 15:22:23 -0400
To: Phil Dibowitz <phil@usc.edu>
cc: kerberos@mit.edu
cc: Ken Raeburn <raeburn@mit.edu>
Errors-To: kerberos-bounces@mit.edu

On Oct 25, 2004, at 15:02, Phil Dibowitz wrote:
>     [libdefaults]
>          ticket_lifetime = 600

This won't do what you think.  First, we're not parsing 
"ticket_lifetime", despite having some indications around that we do.  
Second, the time-interval parsing code requires a unit.  (I think both 
of these will change in the 1.4 release.)

> But according to the man page, you can put a "renew_lifetime" in the
> libdefaults section which defaults to 0 -- bingo! right? So I changed
> the libdefaults section to:
>
>     [libdefaults]
>          ticket_lifetime = 600
>          renew_lifetime = 700

Try "700s" or "700m".

Also check the properties on the client and service principals 
(including the krbtgt principals).  I forget whether max renewable 
lifetime is one of them, but if it is, it would be set when the 
principal is created or when you use "modprinc" in kadmin, and the 
config file specifications won't extend it, only (potentially) further 
limit it.

Ken

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post