Boston Linux & Unix (BLU) Home | Calendar | Mail Lists | List Archives | Desktop SIG | Hardware Hacking SIG
Wiki | Flickr | PicasaWeb | Video | Maps & Directions | Installfests | Keysignings
Linux Cafe | Meeting Notes | Blog | Linux Links | Bling | About BLU

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Active Directory authentication and kerberos timeout



On Dec 8, 2009, at 7:15 PM, John Abreau wrote:
> 
> How do I get the server to keep the trust relationship permanently?

You can't make it permanent but you can make it last a very, very long time.  First, check with the KDC/AD admin and find out what the max renewable life on renewable tickets is.  That is going to be your absolute maximum trust lifetime.  Let's say that is 30 days.  Make your ticket renewable with kinit:

# kinit -r 30d

And that's it.  Your ticket will expire after 24 hours (ticket_lifetime) and then automatically renew with the KDC until the 30-day "lease" expires.

--Rich P.








BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org