summaryrefslogtreecommitdiffstats
path: root/src/lib/kadm5
diff options
context:
space:
mode:
authorGreg Hudson <ghudson@mit.edu>2013-06-06 14:44:30 -0400
committerGreg Hudson <ghudson@mit.edu>2013-06-06 20:09:46 -0400
commit4f551a7ec126c52ee1f8fea4c3954015b70987bd (patch)
treecee645af15058887e48a9d054c806b9db4be3715 /src/lib/kadm5
parent6936d2792fda4d92cb78bcb12fd51d6ea23a746a (diff)
downloadkrb5-4f551a7ec126c52ee1f8fea4c3954015b70987bd.tar.gz
krb5-4f551a7ec126c52ee1f8fea4c3954015b70987bd.tar.xz
krb5-4f551a7ec126c52ee1f8fea4c3954015b70987bd.zip
Refactor KDC renewable ticket handling
Create a new helper to compute the renewable lifetime for AS and TGS requests. This has some minor behavior differences: * We only issue a renewable ticket if the renewable lifetime is greater than the normal ticket lifetime. * We give RENEWABLE precedence over RENEWABLE-OK in determining the requested renewable lifetime, instead of sometimes doing the reverse. * We use the client's maximum renewable life for TGS requests if we have looked up its DB entry. * Instead of rejecting requests for renewable tickets (if the client or server principal doesn't allow it, or a TGS request's TGT isn't renewable), issue non-renewable tickets. ticket: 7661 (new)
Diffstat (limited to 'src/lib/kadm5')
0 files changed, 0 insertions, 0 deletions