ktkt_warnd(1M) System Administration Commands ktkt_warnd(1M)NAME
ktkt_warnd - Kerberos warning daemon
SYNOPSIS
/usr/lib/krb5/ktkt_warnd
DESCRIPTION
ktkt_warnd is a daemon on Kerberos clients that can warn users when their Kerberos tickets are about to expire. It is invoked by inetd when
a ticket-granting ticket (TGT) is obtained for the first time, such as after using the kinit command. ktkt_warnd can be configured through
the /etc/krb5/warn.conf file on the client. In warn.conf, you can specify that you be supplied notice, through syslog, of ticket expira-
tion.
FILES
/etc/krb5/warn.conf Kerberos warning configuration file
SEE ALSO svcs(1), inetadm(1M), inetd(1M), svcadm(1M), warn.conf(4), smf(5), SEAM(5)NOTES
The ktkt_warnd service is managed by the service management facility, smf(5), under the service identifier:
svc:/network/security/ktkt_warn:default
Administrative actions on this service, such as enabling, disabling, or requesting restart, can be performed using svcadm(1M). Responsibil-
ity for initiating and restarting this service is delegated to inetd(1M). Use inetadm(1M) to make configuration changes and to view config-
uration information for this service. The service's status can be queried using the svcs(1) command.
SunOS 5.10 4 Nov 2004 ktkt_warnd(1M)
Check Out this Related Man Page
warn.conf(4) File Formats warn.conf(4)NAME
warn.conf - Kerberos warning configuration file
SYNOPSIS
/etc/krb5/warn.conf
DESCRIPTION
The warn.conf file contains configuration information specifying how users will be warned by the ktkt_warnd daemon about ticket expiration
on a Kerberos client. Credential expiration warnings are sent, by means of syslog, to auth.notice. All other warning messages are sent to
daemon.notice.
Each Kerberos client host must have a warn.conf file in order for users on that host to get Kerberos warnings from the client. Entries in
the warn.conf file must have the following format:
principal syslog | terminal | mail time [email_address]
principal Specifies the principal name to be warned. The asterisk (*) wildcard can be used to specify groups of principals.
syslog Sends the warnings to the system's syslog. Depending on the /etc/syslog.conf file, syslog entries are written to the
/var/adm/messages file and/or displayed on the terminal.
terminal Sends the warnings to display on the terminal.
mail Sends the warnings as email to the address specified by email_address.
time Specifies how much time before the TGT expires when a warning should be sent. The default time value is seconds, but you
can specify h (hours) and m (minutes) after the number to specify other time values.
email_address Specifies the email address at which to send the warnings. This field must be specified only with the mail field.
EXAMPLES
Example 1: Specifying warnings
The following warn.conf entry
* syslog 5m
specifies that warnings will be sent to the syslog five minutes before the expiration of the TGT for all principals. The form of the mes-
sage is:
jdb@ACME.COM: your kerberos credentials expire in 5 minutes
FILES
/usr/lib/krb5/ktkt_warnd Kerberos warning daemon
SEE ALSO ktkt_warnd(1M), syslog.conf(4), SEAM(5)SunOS 5.10 22 Apr 2003 warn.conf(4)
I am little confussed, I have installed a netbackup client on Solaris 10.
The client software has made an entry for bpcd in /etc/inetd.conf file
My question is can I use the following command in Solaris 10 so that inetd.conf is reread and is it save to do this in a production env.
Do I need to... (1 Reply)
(I will not duplicate my post that I create in 'Programming' ( My post ), but the issue also (after C ) is related to Sun Solaris.)
I need to find the warning-codes to be used in the
#pragma warn..
C-code directives to suppress some compilation warnings.
More desciptive explanation you... (2 Replies)
I am setting up Kerberos authentication and this is one of the steps:
1. Open the JBoss startup script.
2. Add the following Java System Properties
-Djava.security.krb5.conf=/disk01/kerb/krb5.conf
-Djavax.security.auth.useSubjectCredsOnly=false
I added these 2 lines and it works in a... (0 Replies)
Hi, was wondering if its possible to change the default warning message text that notifies users that their kerberos ticket is due to expire in xx minutes. I am using Kerberos 5 on Sol 10.
Can't find anything in man pages, so hoping its maybe an undocumented feature. I'd like to make the... (1 Reply)