[32288] in Kerberos

home help back first fref pref prev next nref lref last post

Re: no renewable flag in krb5.conf ?

daemon@ATHENA.MIT.EDU (Guillaume Rousse)
Tue Apr 27 04:07:31 2010

Message-ID: <4BD69B38.5020207@inria.fr>
Date: Tue, 27 Apr 2010 10:07:20 +0200
From: Guillaume Rousse <Guillaume.Rousse@inria.fr>
MIME-Version: 1.0
To: Russ Allbery <rra@stanford.edu>
In-Reply-To: <87r5mj43f5.fsf@windlord.stanford.edu>
Cc: kerberos@mit.edu
Content-Type: multipart/mixed; boundary="===============0358002617=="
Errors-To: kerberos-bounces@mit.edu

This is a cryptographically signed message in MIME format.

--===============0358002617==
Content-Type: multipart/signed; protocol="application/pkcs7-signature";
	micalg=sha1; boundary="------------ms000607050408090405050109"

This is a cryptographically signed message in MIME format.

--------------ms000607050408090405050109
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Le 13/04/2010 20:23, Russ Allbery a =E9crit :
> I assume that you're using my PAM module here, since I think it's the o=
nly
> one that looks at [appdefaults].pam.  (I could be wrong, though; maybe =
the
> Red Hat one does as well.)  Anyway, for mine, you want to use
> renew_lifetime, not renewable:
>=20
>    renew_lifetime=3D<lifetime>
>        Obtain renewable tickets with a maximum renewable lifetime of
>        <lifetime>.  <lifetime> should be a Kerberos lifetime string suc=
h
>        as "2d4h10m" or a time in minutes.  If set, this overrides the
>        Kerberos library default set in the [libdefaults] section of
>        krb5.conf.
>=20
>        This option can be set in krb5.conf and is only applicable to th=
e
>        auth group.
I forgot to thanks both of you for this answer, due to hollidays. It
works like a charm now.

--=20
BOFH excuse #436:

Daemon escaped from pentagram


--------------ms000607050408090405050109--

--===============0358002617==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============0358002617==--

home help back first fref pref prev next nref lref last post