diff options
| author | Jeffrey Altman <jaltman@secure-endpoints.com> | 2003-10-21 22:20:48 +0000 |
|---|---|---|
| committer | Jeffrey Altman <jaltman@secure-endpoints.com> | 2003-10-21 22:20:48 +0000 |
| commit | e3dc77a76f29f0484eab155f4d6789b0a20eb8df (patch) | |
| tree | bd57ff15023d07328528cd99978faeb2b65be2e9 /src/windows/ms2mit/ChangeLog | |
| parent | 06849abbcf92a893127359c8b53295860d40296a (diff) | |
| download | krb5-e3dc77a76f29f0484eab155f4d6789b0a20eb8df.tar.gz krb5-e3dc77a76f29f0484eab155f4d6789b0a20eb8df.tar.xz krb5-e3dc77a76f29f0484eab155f4d6789b0a20eb8df.zip | |
Because of the failure of Windows 2000 and Windows XP to perform proper
ticket expiration time management, the MS Kerberos LSA will return
tickets to a calling application with lifetimes as short as one second.
Tickets with lifetimes less than five minutes can cause problems for
most apps. Tickets with lifetimes less than 20 minutes will trigger the
Leash ticket lifetime warnings.
Instead of accepting whatever tickets are returned by MS LSA from the
cache, if the ticket lifetime is less than 20 minutes force a retrieval
operation bypassing the LSA ticket cache.
ticket: 1962
target_version: 1.3.2
tags: pullup
owner: jaltman@mit.edu
status: resolved
git-svn-id: svn://anonsvn.mit.edu/krb5/trunk@15843 dc483132-0cff-0310-8789-dd5450dbe970
Diffstat (limited to 'src/windows/ms2mit/ChangeLog')
| -rw-r--r-- | src/windows/ms2mit/ChangeLog | 16 |
1 files changed, 16 insertions, 0 deletions
diff --git a/src/windows/ms2mit/ChangeLog b/src/windows/ms2mit/ChangeLog index 1c5a9c45f..f177bb41d 100644 --- a/src/windows/ms2mit/ChangeLog +++ b/src/windows/ms2mit/ChangeLog @@ -1,3 +1,19 @@ +2003-10-21 Jeffrey Altman <jaltman@mit.edu> + + * ms2mit.c: + + Because of the failure of Windows 2000 and Windows XP to perform + proper ticket expiration time management, the MS Kerberos LSA will + return tickets to a calling application with lifetimes as short as + one second. Tickets with lifetimes less than five minutes can cause + problems for most apps. Tickets with lifetimes less than 20 minutes + will trigger the Leash ticket lifetime warnings. + + Instead of accepting whatever tickets are returned by MS LSA from + the cache, if the ticket lifetime is less than 20 minutes force a + retrieval operation bypassing the LSA ticket cache. + + 2003-07-16 Jeffrey Altman <jaltman@mit.edu> * ms2mit.c: |
