[2387] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Question about keytab timestamp field

daemon@ATHENA.MIT.EDU (Joe Pato)
Fri Nov 20 18:53:28 1992

From: pato@APOLLO.HP.COM (Joe Pato)
Date: Fri, 20 Nov 92 18:40:05 EST
To: bjaspan@Athena.MIT.EDU ("Barry Jaspan")
Cc: kerberos@Athena.MIT.EDU
In-Reply-To: bjaspan@Athena.MIT.EDU ("Barry Jaspan"), fri, 20 nov 92 15:53:15

    
    The timestamp field in a V5 keytab entry appears to be the time it was
    extracted from the database, rather than the time the key was last
    changed (useful) or that the principal was created (slightly less
    useful).  Can someone explain why this decision was made?
    
    Barry Jaspan
    Aktis, Inc.
    
The timestamp field in the V5 keytab entry is the time the entry was
added to the keytable.  The DCE added this feature for a number of reasons - the
most direct was to know which key is the newest in the keytable.  Since
key version numbers wrap at 255, the version number is not enough.  In our
environment the time the key was written to the key table is effectively the
same time it is set in the KDC (we abstract access to the kerberos environment
and the facility that manages keys for servers operates on both databases -
making a direct change to the keytable and then a remote change to the KDC.)

                    -- Joe Pato
                       Distributed Computing Program / East
                       Hewlett-Packard Company
                       pato@apollo.hp.com


-------

home help back first fref pref prev next nref lref last post