[28315] in Kerberos

home help back first fref pref prev next nref lref last post

Re: clock skew

daemon@ATHENA.MIT.EDU (Danny Mayer)
Fri Aug 31 08:37:16 2007

Message-ID: <46D80AE8.9030804@ntp.isc.org>
Date: Fri, 31 Aug 2007 08:34:48 -0400
From: Danny Mayer <mayer@ntp.isc.org>
MIME-Version: 1.0
To: a a <nonamepa@yahoo.fr>
In-Reply-To: <406517.34929.qm@web26611.mail.ukl.yahoo.com>
X-kostecke.net-MailScanner-From: mayer@ntp.isc.org
Cc: kerberos@mit.edu
Reply-To: mayer@ntp.isc.org
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

a a wrote:
> Hi,
> I'd like to authenticate a client with the krb server with a time diffference > 5 min.
> In native, I have the message : "clockskew too great....."
> With the clocskew propertie in /etc/krb5.conf (of both machines), logs messages are OK on the server but the authentication doesn't work either...
> Can yu tell me how to use clockskew ?
> 

You can't. It would violate the RFC's. You should be looking at how to
synchronize your clocks. NTP is the usual and best solution.

Danny
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post