[8061] in Kerberos

home help back first fref pref prev next nref lref last post

Re: 0 seconds initialization (round 2)

daemon@ATHENA.MIT.EDU (Christopher Seawood)
Thu Sep 19 18:17:36 1996

Date: Thu, 19 Sep 1996 14:58:07 -0700 (PDT)
From: Christopher Seawood <cseawood@qualcomm.com>
Reply-To: Christopher Seawood <cseawood@qualcomm.com>
To: Barry Jaspan <bjaspan@MIT.EDU>
Cc: kerberos@MIT.EDU
In-Reply-To: <9609191844.AA28071@DUN-DUN-NOODLES.MIT.EDU>

On Thu, 19 Sep 1996, Barry Jaspan wrote:

> 
> The max_life field of kdc.conf only affects principals when they are
> *created*; after that, the principal has its own local copy of
> max_life that must be modified with modify_principal.  I am guessing
> that you did not re-create your database after adding the max_life
> field to kdc.conf.  When the database was created, the default
> max_life therefore was used, and the default in beta 7 is (brokenly)
> 0.  As a resut, krbtgt's max_life was 0 until you explicitly changed
> it.
> 
This is incorrect. The kdc.conf was properly installed *before* I ran
kdb5_util create -s. I'm starting a new database (again). Currently, I'm
under the impression that the max_life in the kdc.conf is being ignored
completely. I tried it with 'max_life = 10h 0m 0s' and 'max_life = 10
hours'. Both did the same thing: max_life = 0.

-----
Chris Seawood <cseawood@qualcomm.com> - Software Engineer / Unix Sysadmin
http://www.qualcomm.com/~cseawood/    - Prince Fanatic / Linux Advocate
Opinions stated are NOT an (un)official representation of QUALCOMM Incorporated




home help back first fref pref prev next nref lref last post