[39629] in Kerberos

home help back first fref pref prev next nref lref last post

KEYRING ccache can hide valid tickets when it contains expired ticket

daemon@ATHENA.MIT.EDU (Ao Shen via Kerberos)
Sun Oct 11 11:19:05 2026

Date: Sun, 11 Oct 2026 23:18:30 +0800
To: kerberos@mit.edu
Message-ID: <asui1ivG5JbMTvdy@PieceMoissance>
MIME-Version: 1.0
Content-Disposition: inline
From: Ao Shen via Kerberos <kerberos@mit.edu>
Reply-To: Ao Shen <sa22@mails.tsinghua.edu.cn>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Hello list,

I'm trying to use KEYRING as default ccache and noticed that when there is a
service ticket expired, `klist` would truncate the list of available tickets
in my ccache with an error message:

klist: No credentials cache found while retrieving a ticket

However, after a while, the error would be gone and everything returned
normal.

Running `strace -e trace=keyctl -e raw=keyctl klist` resulted in the following
trace:

<snipped>
Ticket cache: KEYRING:persistent:1000:1000
Default principal: <redacted>

Valid starting       Expires              Service principal
keyctl(0xb, 0x3bcd9d82, 0, 0, 0x1)      = 0x20
keyctl(0xb, 0x3bcd9d82, 0x555b0ccc3300, 0x20, 0x21) = 0x20
keyctl(0xa, 0x3bcd9d82, 0x7fb2398031cb, 0x7fb2398031b5, 0) = 0x2d49e281
keyctl(0xb, 0x1cd27e1, 0, 0, 0)         = 0x2ac
keyctl(0xb, 0x1cd27e1, 0x555b0ccc3d20, 0x2ac, 0x2ad) = 0x2ac
2026-10-11T19:40:52  2026-10-11T19:50:52  host/<redacted>
keyctl(0xb, 0x20d54b4d, 0, 0, 0x555b0ccbf030) = -1 EKEYEXPIRED (Key has expired)
klist: No credentials cache found while retrieving a ticket

It looks like that krcc_next_cred() would return KRB5_FCC_NOFILE when it
encountered an expired key when it would be fine to ignore it and continue.

According to kernel documentation[1], expired key can be retained in keyring
for at most sys.kernel.keys.gc_delay seconds. After GC, the key would be
removed, then krcc_next_cred() would work again.

My kerberos version: Kerberos 5 release 1.22.2
My operation system: Linux 6.18.52-gentoo #1 SMP PREEMPT_DYNAMIC Mon Sep 28 16:57:55 CST 2026 x86_64 AMD Ryzen 9 9950X3D 16-Core Processor AuthenticAMD GNU/Linux

[1]: https://www.kernel.org/doc/html/v7.2/security/keys/core.html#garbage-collection

--

Ao Shen

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post