[28293] in Kerberos
Re: regarding clock skew difference between client and KDC
daemon@ATHENA.MIT.EDU (Danny Mayer)
Thu Aug 23 22:54:40 2007
Message-ID: <46CE4811.7020200@ntp.isc.org>
Date: Thu, 23 Aug 2007 22:53:05 -0400
From: Danny Mayer <mayer@ntp.isc.org>
MIME-Version: 1.0
To: eswars <eswars@huawei.com>
In-Reply-To: <006001c7e483$74221d70$3e19120a@china.huawei.com>
X-kostecke.net-MailScanner-From: mayer@ntp.isc.org
Cc: kerberos@mit.edu
Reply-To: mayer@ntp.isc.org
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
eswars wrote:
> Hi,
>
>
>
> I am using MIT Kerberos 2.6.5 libraries in windows machine. I am
> using Active Directory win 2003.
>
> I wanted to authenticate user even when clock skew difference more then 5
> min.
>
That violates the RFC requirements. No server will or should allow you
to do that. Why are you not synchronizing your clocks? NTP is available
on just about all platforms so there's no reason not to use it.
>
> Please give me some suggestion how I can do this.
>
You can't.
Danny
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos