---
Francis Augusto Medeiros-Logeay
Oslo, Norway

On 2022-04-07 15:26, Kees Bakker via FreeIPA-users wrote:


Have you looked at SSSD's krb5_renew_interval and krb5_renewable_lifetime?
On my PC I changed it to:

/etc/sssd/sssd.conf
    [domain/example.com]
    ...
    krb5_renewable_lifetime = 60d
    krb5_renew_interval = 6h

I don't really need it anymore because I'm now locking my PC when I go
home :-). And when I get
back I have to enter my password, after which there is a new TGT.

Thanks Kees. That doesn't cut it, as it doesn't really get a new TGT besides the lifetime that is set by the server. If that is 7d, so setting it higher on the client won't help. Besides the renewal_interval only works for tickets inside the renewable_lifetime.

Best,
Francis
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to