delete_principal does not delete the principal from the Database file

Aravind Jerubandi aravind.jerubandi at gmail.com
Mon Jul 16 13:48:08 EDT 2012


Hi,

We are using Kerberos 5 in our production environment. We had 5.3M user
accounts and our principal database file size was 4.4G.

Recently we deleted large number of records and currently we have 0.95M
user accounts. But the principal file size is still 4.4G.

Looks like KDC does not delete the principals from the database file, but
just disables it. Is there a way to permanently delete the principals and
reduce the principal file size?

(the number of accounts info is taken from the attribute value 'Reference
count' which we get with the 'get_policy' command)

-- 
Thanks & Regards,
J.Aravind


More information about the Kerberos mailing list