kerberos credential file name truncated

Solution Unverified - Updated -

Issue

We have a number of RHEL-6 systems we connect to via ssh. Users are authenticated through pam_sss and sssd is configured to authenticate against Kerberos krb5.
In sssd.conf we have:

krb5_ccachedir = /tmp
krb5_ccname_template = FILE:%d/krb5cc_%U_XXXXXX

However when the user logs in through ssh the KRB5CCNAME environment variable sometimes is not set and the ticket cache file is set to the krb5 default /tmp/krb5cc_%U

Environment

  • Red Hat Enterprise Linux 6
  • Red Hat Enterprise Linux 7
  • sssd configured to authenticate against Active Directory

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content