Administration
Attributes Tab (Principal Information window)
postdatable ticket. If this attribute is set for a service principal, the server can issue postdated service tickets for the service.
Allow Renewable Tickets
The Allow Renewable attribute specifies if a principal is allowed to renew its tickets. Renewable tickets are those that a principal can
The Allow Renewable attribute applies to both user and service principals. If this attributes is set for a user principal, then the principal can be issued a renewable ticket. If this attribute is set for a service principal, the server can issue a renewable ticket for the service.
The maximum renew time is set on the General tab of the Principal Information window.
Allow Forwardable Attribute The Allow Forwardable attribute specifies if a principal is allowed ticket forwarding. Forwarding is a mechanism that sends a TGT from one network host to another. The forwarded TGT can be used to generate a new service ticket on the second host system on the principal’s behalf.
The Allow Forwardable attribute applies to both user and service principals. If this attribute is set for a user principal, the principal can be issued a forwarded or forwardable ticket. If this attribute is set for a service principal, the server can issue a forwarded service ticket for the service.
Allow Proxy Attribute The Allow Proxy attribute specifies if a principal is allowed proxy tickets. Proxy tickets allow applications that a principal accesses with a TGT to request a special class of service ticket. This type of service ticket can be moved to another host on the network that acts on the principal’s behalf. For example, a print service printing a file.
The Allow Proxy attribute applies to both user and service principals. If this attributes is set for a user principal, the principal can be issued a proxy ticket. If this attribute is set for a service principal, the server can issue a proxy service ticket for the service.
146 | Chapter 6 |