[35866] in Kerberos
Re: Fwd: Kerberos5 ticket auto renewal
daemon@ATHENA.MIT.EDU (Wendy Lin)
Tue Mar 18 10:00:40 2014
MIME-Version: 1.0
In-Reply-To: <5328420C.1010405@oracle.com>
Date: Tue, 18 Mar 2014 15:00:24 +0100
Message-ID: <CA+j=ERp8_iCoOf4_SKwYQ4KLJjCSpr=Pt04u-9PBGJF3vS3CiA@mail.gmail.com>
From: Wendy Lin <wendlin1974@gmail.com>
To: Tomas Kuthan <tomas.kuthan@oracle.com>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
On 18 March 2014 13:54, Tomas Kuthan <tomas.kuthan@oracle.com> wrote:
> Hi Wendy,
>
> (I can only comment on Solaris)
>
> I suppose, you are referring to automatic renewal of tickets by
> ktkt_warnd. ktkt_warn service is enabled by default, but there are
> upgrade scenarios, were you can end up with ktkt_warn disabled. Run
> 'svcs ktkt_warn' to confirm.
>
> If ktkt_warn is up and running, it could also be user-principal
> discrepancy. IIRC, ktkt_warn won't register a warning for a principal
> that doesn't map to your uid (such as running 'kinit username' as root).
1. Where can I find ktkt_warn for Linux?
2. ktkt_warn seems to be broken in Illumos and Solaris 11, see
https://www.illumos.org/issues/3271
Wendy
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos