[22754] in Kerberos
RE: Renewable Tickets
daemon@ATHENA.MIT.EDU (Kevin Coffman)
Mon Oct 25 16:56:48 2004
From: "Kevin Coffman" <kwc@citi.umich.edu>
To: "'Phil Dibowitz'" <phil@usc.edu>
Date: Mon, 25 Oct 2004 16:54:31 -0400
Message-ID: <00a801c4bad4$d36f3410$6400000a@citi.umich.edu>
MIME-Version: 1.0
Content-Type: text/plain;
charset="US-ASCII"
Content-Transfer-Encoding: 7bit
In-Reply-To: <20041025205104.GE26380@usc.edu>
cc: kerberos@mit.edu
Reply-To: kwc@citi.umich.edu
Errors-To: kerberos-bounces@mit.edu
> -----Original Message-----
> From: Phil Dibowitz [mailto:phil@usc.edu]
> Sent: Monday, October 25, 2004 4:51 PM
> To: Kevin Coffman
> Cc: kerberos@MIT.EDU
> Subject: Re: Renewable Tickets
>
> On Mon, Oct 25, 2004 at 04:46:21PM -0400, Kevin Coffman wrote:
> > > > Also check the properties on the client and service principals
> > > > (including the krbtgt principals). I forget whether max renewable
> > > > lifetime is one of them, but if it is, it would be set when the
> > > > principal is created or when you use "modprinc" in kadmin, and the
> > > > config file specifications won't extend it, only (potentially)
> further
> > > > limit it.
> > >
> > > You had me all excited for a minute... but no:
> > >
> > > kadmin: getprinc phil
> > > ...
> > > Maximum renewable life: 7 days 00:00:00
> >
> >
> > That's the client. What about
> > getprinc krbtgt/ISD.USC.EDU@ISD.USC.EDU ?
>
> Aha!
>
> Maximum renewable life: 0 days 00:00:00
>
> So... "krbtgt" is the principal for... the domain? I'm still catching up
> on
> Kerberos here.
It is the principal for the Ticket Granting Service.
> so a
> modprinc -maxrenewlife 7d krbtgt/ISD.USC.EDU@ISD.USC.EDU
>
> Should fix this?
Yes :-)
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos