Re: [Freeipa-users] Laptop user

2014-11-20 Thread Jakub Hrozek
On Thu, Nov 20, 2014 at 05:04:02PM +0800, Thomas Lau wrote: Does anyone know what's the behavior look like if a mobile user (laptop) being disconnected from Kerberos for too long even cache is enabled by default in our environment? SSSD caches the user data and if cache_credentials is enabled,

Re: [Freeipa-users] Laptop user

2014-11-20 Thread Thomas Lau
What will happen if laptop haven't turn on for a long time and ticket expired with cache and store password enabled? Does user unable to login after expired? On Thu, Nov 20, 2014 at 5:10 PM, Jakub Hrozek jhro...@redhat.com wrote: On Thu, Nov 20, 2014 at 05:04:02PM +0800, Thomas Lau wrote:

Re: [Freeipa-users] Laptop user

2014-11-20 Thread Jakub Hrozek
On Thu, Nov 20, 2014 at 05:19:57PM +0800, Thomas Lau wrote: What will happen if laptop haven't turn on for a long time and ticket expired with cache and store password enabled? Does user unable to login after expired? SSSD doesn't use the ticket to authenticate in offline case, so sssd doesn't

Re: [Freeipa-users] Laptop user

2014-11-20 Thread Thomas Lau
Thanks, that solve my concern! On Thu, Nov 20, 2014 at 5:35 PM, Jakub Hrozek jhro...@redhat.com wrote: On Thu, Nov 20, 2014 at 05:19:57PM +0800, Thomas Lau wrote: What will happen if laptop haven't turn on for a long time and ticket expired with cache and store password enabled? Does user