[SERVER-7123] Check Kerberos ticket expiration when authz checking Created: 24/Sep/12 Updated: 06/Dec/22 |
|
| Status: | Backlog |
| Project: | Core Server |
| Component/s: | Security |
| Affects Version/s: | None |
| Fix Version/s: | None |
| Type: | New Feature | Priority: | Major - P3 |
| Reporter: | Eric Milkie | Assignee: | Backlog - Security Team |
| Resolution: | Unresolved | Votes: | 0 |
| Labels: | kerberos, platforms-re-triaged | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Issue Links: |
|
||||
| Assigned Teams: |
Server Security
|
||||
| Participants: | |||||
| Comments |
| Comment by Andreas Nilsson [ 06/Mar/14 ] |
|
You mean re-checking of the ticket expiration during an active user session? I think this is easiest implemented using proper session management with a configurable session timeout. |
| Comment by Eric Milkie [ 06/Mar/14 ] |
|
Expiration of the Kerberos ticket, I believe. If your ticket expires, right now you can continue operating as if it were still valid. |
| Comment by Andreas Nilsson [ 06/Mar/14 ] |
|
check expirations of what? |