[8061] in Kerberos
Re: 0 seconds initialization (round 2)
daemon@ATHENA.MIT.EDU (Christopher Seawood)
Thu Sep 19 18:17:36 1996
Date: Thu, 19 Sep 1996 14:58:07 -0700 (PDT)
From: Christopher Seawood <cseawood@qualcomm.com>
Reply-To: Christopher Seawood <cseawood@qualcomm.com>
To: Barry Jaspan <bjaspan@MIT.EDU>
Cc: kerberos@MIT.EDU
In-Reply-To: <9609191844.AA28071@DUN-DUN-NOODLES.MIT.EDU>
On Thu, 19 Sep 1996, Barry Jaspan wrote:
>
> The max_life field of kdc.conf only affects principals when they are
> *created*; after that, the principal has its own local copy of
> max_life that must be modified with modify_principal. I am guessing
> that you did not re-create your database after adding the max_life
> field to kdc.conf. When the database was created, the default
> max_life therefore was used, and the default in beta 7 is (brokenly)
> 0. As a resut, krbtgt's max_life was 0 until you explicitly changed
> it.
>
This is incorrect. The kdc.conf was properly installed *before* I ran
kdb5_util create -s. I'm starting a new database (again). Currently, I'm
under the impression that the max_life in the kdc.conf is being ignored
completely. I tried it with 'max_life = 10h 0m 0s' and 'max_life = 10
hours'. Both did the same thing: max_life = 0.
-----
Chris Seawood <cseawood@qualcomm.com> - Software Engineer / Unix Sysadmin
http://www.qualcomm.com/~cseawood/ - Prince Fanatic / Linux Advocate
Opinions stated are NOT an (un)official representation of QUALCOMM Incorporated