[19177] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Possible enhancement request for extra krb5.conf parameter

daemon@ATHENA.MIT.EDU (Nico Williams)
Thu May 14 11:22:58 2015

Date: Thu, 14 May 2015 10:22:39 -0500
From: Nico Williams <nico@cryptonector.com>
To: Jeffrey Altman <jaltman@secure-endpoints.com>
Message-ID: <20150514152238.GA7287@localhost>
MIME-Version: 1.0
Content-Disposition: inline
In-Reply-To: <5554B2CE.6020603@secure-endpoints.com>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Thu, May 14, 2015 at 10:35:58AM -0400, Jeffrey Altman wrote:
> On 5/13/2015 5:14 PM, Neng Xue wrote:
> > As far as I can tell from Solaris kerberos, if there is no renewable 
> > lifetime specified from kinit command line. It will then take the 
> > maximum renewable lifetime (7 days by default).
> 
> From a usability and configuration perspective if the krb5.conf does not
> specify [libdefault] ticket and renew lifetimes,then the client library
> should not impose a limit and should request the maximum value.  The
> ticket lifetime and the renew lifetime should be selected by the KDC
> based upon the configured parameters for the client principal, krbtgt
> principal or other service principal.

+1
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post