[23015] in Kerberos
Re: your mail
daemon@ATHENA.MIT.EDU (Thomas A. La Porte)
Tue Dec 7 17:51:52 2004
Date: Tue, 7 Dec 2004 14:51:09 -0800 (PST)
From: "Thomas A. La Porte" <tlaporte@anim.dreamworks.com>
To: Frederic Medery <dist-list@lexum.umontreal.ca>
In-Reply-To: <50914.24.201.52.131.1102382632.squirrel@24.201.52.131>
Message-ID: <Pine.LNX.4.44.0412071447210.5687-100000@sunset.anim.dreamworks.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
The stock RedHat module does not appear to implement the
refresh_creds properly[*], rather it gets tickets into a new
credentials cache, which is *effectively* unavailable from the
user's standpoint b/c the KRB5CCNAME variable is not updated.
The pam_krb5 module available from sourceforge does reget
credentials with the 'refresh_creds' option and puts them into
the credentials cache currently defined in the KRB5CCNAME
variable.
-- Tom
[*] Where *properly* here is simply being defined as the way
way *I* would have expected it to work. Would that the
world were always thusly defined :-)
Thomas A. La Porte, DreamWorks Animation SKG
<mailto:tlaporte@anim.dreamworks.com>
On Mon, 6 Dec 2004, Frederic Medery wrote:
>First of all, thank to all of the great input find here !!
>
>Before adding beta users to my kerberos/ldap server, I still have some
>problems remaining.
>
>Linux users do not halt or log off all the time (because of stuff running
>in consoles for example). So is there a way (pam_krb5 ? ) to renew TGT
>when we enter password from xlock, xscreensaver. Stations are alreasy
>configured to user pam_krb5 for login (sys-auth) os perhaps it's just an
>pam_krb5 option to add to the config file ?
>
>
>thanks !
>
>________________________________________________
>Kerberos mailing list Kerberos@mit.edu
>https://mailman.mit.edu/mailman/listinfo/kerberos
>
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos