[krbdev.mit.edu #1962] windows ms2mit.exe: do not allow MS LSA to provide tickets with short lifetimes

Jeffrey Altman via RT rt-comment at krbdev.mit.edu
Tue Oct 21 18:16:22 EDT 2003


Because of the failure of Windows 2000 and Windows XP to perform proper
ticket expiration time management, the MS Kerberos LSA will return
tickets to a calling application with lifetimes as short as one second.
 Tickets with lifetimes less than five minutes can cause problems for
most apps.  Tickets with lifetimes less than 20 minutes will trigger the
Leash ticket lifetime warnings.

Instead of accepting whatever tickets are returned by MS LSA from the
cache, if the ticket lifetime is less than 20 minutes force a retrieval
operation bypassing the LSA ticket cache.





More information about the krb5-bugs mailing list