[22769] in Kerberos
krb5.conf variations, was: Renewable Tickets
daemon@ATHENA.MIT.EDU (Henry B. Hotz)
Thu Oct 28 18:17:51 2004
In-Reply-To: <200410252304.i9PN4xZZ024061@pch.mit.edu>
Mime-Version: 1.0 (Apple Message framework v619)
Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed
Message-Id: <D7758C17-292E-11D9-B611-000A95CA746C@jpl.nasa.gov>
Content-Transfer-Encoding: 7bit
From: "Henry B. Hotz" <hotz@jpl.nasa.gov>
Date: Thu, 28 Oct 2004 15:15:14 -0700
To: eandres@mars.asu.edu
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
On Oct 25, 2004, at 4:04 PM, kerberos-request@mit.edu wrote:
> First, I'd like to mention I was mistaken when I said the 'libdefaults'
> section, I meant 'appdefaults', such as:
>
> [appdefaults]
> ticket_lifetime = 30days
> renew_lifetime = 180days
>
> or alternatively, within a 'kinit' subgroup.
I'm running with:
[appdefaults]
renewable = true
[libdefaults]
renew_lifetime = 7d
on my Solaris clients and it seems to do the right thing (against a
Heimdal kdc). Looking at the Solaris 9 krb5.conf man page I see
max_renewable_life as an [appdefaults] option, but nothing else.
Perhaps the renew_lifetime line isn't needed?
I suspect the renew_lifetime line is a carryover from some other
krb5.conf. In Heimdal it can go in either section and "7d" is OK (vice
7days).
An MIT 1.3 man page does not mention max_renewable_life, and puts
renew_lifetime in [libdefaults] only.
I suppose I shouldn't complain. Everyone really is pretty compatible
if you're willing to deal with the details. That indicates serious
effort on the part of all the implementors, free and commercial alike.
------------------------------------------------------------------------
----
The opinions expressed in this message are mine,
not those of Caltech, JPL, NASA, or the US Government.
Henry.B.Hotz@jpl.nasa.gov, or hbhotz@oxy.edu
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos