Kerberos Server Version 3.2.2 Release Notes (5900-1855, July 2011)
Defect fixes
The following defects are fixed in Kerberos Client Version 3.2.2:
• QXCR1001015514: kdcd fails to start up at boot intermittently
Symptom
kdcd (1m) fails intermittently to start at boot.
Defect description
Improper shutdown of kdcd (1m) leaves a residual kdcd.pid file which causes the kdcd (1m)
startup to fail.
Resolution
This issue is fixed.
• QXCR1001101782: HP-UX: When running "kinit -R", Kerberos tickets expire when they should
not
Symptom
Renewal of valid Kerberos tickets fail with the following error: “kinit(v5): Ticket expired while
renewing credentials".
Defect description
Some functions are not thread safe. This causes the failure when simultaneous requests for
renewal of Kerberos tickets are received.
Resolution
This issue is fixed.
• QXCR1001077707 : Timestamp of log file is incorrect when -l option is used
Symptom
Timestamp in kdcd (1m) log file is invalid.
Defect description
The timestamp in the log files of kdcd (1m), kadmind (1m) and kpropd (1m) will become
invalid when the log location is specified using the —l option.
Resolution
This issue is fixed.
Known problems and workarounds
• Problem
If the hpKrbPrincipal attribute is not indexed, the performance of the Kerberos server may
degrade.
Workaround
Index the LDAP database with the Principal names.
• Problem
If the connection to the LDAP server is terminated the Kerberos server may fail to respond to
client requests.
Workaround
Restart the Kerberos server.
• Problem
The kpasswd command is not supported in the IPv6 environment.
Workaround
8 Announcement