[krbdev.mit.edu #1338] getting tickets that expire before start date

Arun A Tharuvai via RT rt-comment at krbdev.mit.edu
Fri Jan 24 14:49:19 EST 2003


I accidentally tried getting negative length kerberos tickets (both v5
and v4), and it succeeded, giving me krb5 tickets that expired before
they were valid, and krb4 tickets that lasted for exactly 5 minutes.

Arun

arun at w20-spare-pokemon:~$ kinit aatharuv -5 -4  -l -100d -r 100d
Password for aatharuv at ATHENA.MIT.EDU: 
kinit(v524): Ticket expired getting V5 credentials
arun at w20-spare-pokemon:~$ klist
Ticket cache: FILE:/tmp/krb5cc_1000
Default principal: aatharuv at ATHENA.MIT.EDU

Valid starting     Expires            Service principal
01/24/03 14:47:19  10/16/02 15:47:19  krbtgt/ATHENA.MIT.EDU at ATHENA.MIT.EDU
        renew until 01/31/03 14:47:19


Kerberos 4 ticket cache: /tmp/tkt1000
Principal: aatharuv at ATHENA.MIT.EDU

  Issued              Expires             Principal
01/24/03 14:47:22  01/24/03 14:52:22  krbtgt.ATHENA.MIT.EDU at ATHENA.MIT.EDU

-- 
Arun A Tharuvai
aatharuv (at) mit (dot) edu
aat (at) alum (dot) mit (dot) edu


More information about the krb5-bugs mailing list