[krbdev.mit.edu #8579] duplicate caching of some cross-realm TGTs

Greg Hudson via RT rt-comment at krbdev.mit.edu
Mon Apr 24 16:35:36 EDT 2017


For client-driven cross-realm scenarios, I believe we should cache the 
TGTs we ask for, but not alternate TGTs.  If we cache alternate TGTs, we 
could have the same kind of scenario where we repeatedly cache an 
alternate TGT because the overall TGS operation fails.



More information about the krb5-bugs mailing list