[22752] in Kerberos
RE: Renewable Tickets
daemon@ATHENA.MIT.EDU (Kevin Coffman)
Mon Oct 25 16:48:26 2004
From: "Kevin Coffman" <kwc@citi.umich.edu>
To: "'Phil Dibowitz'" <phil@usc.edu>
Date: Mon, 25 Oct 2004 16:46:21 -0400
Message-ID: <009901c4bad3$af1ebeb0$6400000a@citi.umich.edu>
MIME-Version: 1.0
Content-Type: text/plain;
charset="US-ASCII"
Content-Transfer-Encoding: 7bit
In-Reply-To: <20041025195250.GT26380@usc.edu>
cc: kerberos@mit.edu
Reply-To: kwc@citi.umich.edu
Errors-To: kerberos-bounces@mit.edu
> > Also check the properties on the client and service principals
> > (including the krbtgt principals). I forget whether max renewable
> > lifetime is one of them, but if it is, it would be set when the
> > principal is created or when you use "modprinc" in kadmin, and the
> > config file specifications won't extend it, only (potentially) further
> > limit it.
>
> You had me all excited for a minute... but no:
>
> kadmin: getprinc phil
> ...
> Maximum renewable life: 7 days 00:00:00
That's the client. What about
getprinc krbtgt/ISD.USC.EDU@ISD.USC.EDU ?
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos