> I recently committed a change to stop checking for context expiration
> times in the krb5 GSS mech's wrap and unwrap functions.  From the
> commit message:

In an ideal world, I would argue that app's should renew tgt's and rekey sessions transparently as needed.  However in practice it seems to me that most services will allow a session or operation to continue to completion, and at most enforce ticket expiration for new operations.

+1, since it seems to match current practice better.

