RFR 8058290: JAAS Krb5LoginModule has suspect ticket-renewal logic, relies on clockskew grace

Weijun Wang weijun.wang at oracle.com
Thu Jun 25 08:21:36 UTC 2015


Please review the code change at

    http://cr.openjdk.java.net/~weijun/8058290/webrev.00/

After this fix, a "renewTGT=true" in JAAS config for Krb5LoginModule 
means "renew if old enough", as suggested by the bug reporter [1].

Thanks
Max

[1] https://bugs.openjdk.java.net/browse/JDK-8058290



More information about the security-dev mailing list