Red Hat Bugzilla – Bug 1287119
RFE: please add support for TGT lifetime notifications
Last modified: 2017-07-19 08:41:15 EDT
Description of problem:
Currently, krb5-auth-dialog only supports notifications based on expiring TGTs. In our case TGT never expires as it is being automatically renewed by the SSSD daemon - until it hits the lifetime period.
It would be therefore more beneficial if we could configure krb5-auth-dialog the way that it warns user that the Kerberos ticket lifetime is approaching.
Also in cases where user has obtained a renewable TGT, this dialog should not prompt for password - instead it should perhaps offer a possibility to perform renewal on user behalf automatically.
This would be best served by the InfoPipe API of SSSD and overall the desktop integration Alexander is working on.
That would, indeed. But that seems to be quite a long run project which will hardly make it into RHEL-7. What I am looking for here is something quick and relatively easy fix for RHEL-6 and/or 7 which can serve in the mean time.