[29153] in Kerberos
Unable to change lifetime with MIT krb5
daemon@ATHENA.MIT.EDU (vandegrift@gmail.com)
Sun Jan 27 22:15:15 2008
From: vandegrift@gmail.com
Date: Sun, 27 Jan 2008 19:01:17 -0800 (PST)
Message-ID: <d013f562-295b-427d-b303-90d288e84bff@f10g2000hsf.googlegroups.com>
Mime-Version: 1.0
X-Complaints-To: groups-abuse@google.com
Complaints-To: groups-abuse@google.com
To: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Hi everyone,
I have a simple MIT Kerberos config. One KDC/KAS, a handful of
client. I have a principal that I'd like to allow 24h expiration
times on tickets.
My kdc.conf has "max_life = 24h 0m 0s", but if I run "kinit -l 24h", I
still get the default 10h expiration time.
I noticed that the principal had been created with a 10h max life, so
I did "modprinc -maxlife '24 hours' ross". The new lifetime is
reflected in the getprinc output.
Still, kinit only gets me a 10h ticket. What gives?
I'm using the krb5 packages from Debian, if that makes a difference.
Thanks!
Ross
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos