[27541] in Kerberos
Re: DST Time change
daemon@ATHENA.MIT.EDU (Sam Hartman)
Mon Mar 5 22:28:14 2007
From: Sam Hartman <hartmans@mit.edu>
To: mayer@ntp.isc.org
Date: Mon, 05 Mar 2007 22:27:54 -0500
In-Reply-To: <45ECDC56.8080305@ntp.isc.org> (Danny Mayer's message of "Mon, 05
Mar 2007 22:13:26 -0500")
Message-ID: <tslslcj126d.fsf@cz.mit.edu>
MIME-Version: 1.0
Cc: "Edgecombe, Jason" <jwedgeco@uncc.edu>, kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
>>>>> "Danny" == Danny Mayer <mayer@ntp.isc.org> writes:
Danny> Well, yes, in a way. But the biggest affect, as long as you
Danny> don't do anything during the changeover is that your syslog
Danny> or eventlog will be off by an hour along with the display
Danny> of your clock, files and anything else that displays a
Danny> timestamp. My point was that Kerberos uses UTC. Anything
Danny> else would prevent Kerberos from working in the first
Danny> place.
>> This will break Kerberos. My recommendation is to find out how
>> to set the clockskew for your implementation to some value
>> greater than an hour and do that.
>>
Danny> Well that's what we keep telling people. Contact the O/S
Danny> vendor and get whatever fixes are necessary for your
Danny> version of the O/S.
No, I'm not talking about an OS patch. Kerberos has a parameter
called clockskew which is the maximum difference between the clock of
the client and the server. You can tune this parameter yourself.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos