NOTE

Administering the Kerberos Server

Rules for Setting Maximum Ticket Lifetime

Rules for Setting Maximum Ticket Lifetime

Maximum ticket lifetime indicates the maximum lifetime for which a ticket can be issued to the principal. You can specify the maximum ticket lifetime value in the General>Maximum Ticket Lifetime text box.

The format for the ticket lifetime is as follows:

[Nw] [Nd] [Nh] [Nm]

where:

N

Indicates an integer.

w, d, h, m Identifies the unit of time: weeks, days, hours, or minutes, respectively.

A number without a suffix w,d,h, or m is interpreted as hours.

Spaces are not allowed between the number and the suffix.

Following are some examples for denoting the maximum ticket lifetime:

1d3h is 1 day and 3 hours.

9h18m is 9 hours and 18 minutes.

26 is 26 hours.

You can also express the time units by using full words. For example, 1day is the same as 1d. You can also use the keywords week, day, hour, and minute to denote w, d, h, or m, respectively.

The maximum lifetime for a ticket issued to any principal in any given realm is controlled by the settings for the reserved principal krbtgt/REALM@REALM.

Chapter 8

155

Page 155
Image 155
HP UX Kerberos Data Security Software manual Rules for Setting Maximum Ticket Lifetime