Forum Discussion
Julio_Navarro
Cirrostratus
Mar 26, 2015Kerberos Caching Option
Hello;
I have successfully have my users authenticating using Kerberos based on the following document:
https://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-authenticati...
Seth_Cooper
Employee
Mar 26, 2015The default ticket lifetime is 600 minutes (10 hours) in the SSO > Kerberos configuration. The online help shows the following for the "Ticket Lifetime" settings.
Displays, in minutes (for example, 600 minutes would equate to 10 hours), the lifetime of Kerberos tickets obtained for the user. The value represents the maximum ticket lifetime, and the actual lifetime may be less by up to 1 hour. This is because user's ticket lifetime is the same as TGT lifetime. The TGT is a Kerberos Ticket Granting Ticket obtained for the delegation account specified in this configuration. The new TGT is fetched every time when current the TGT for that account is older than one hour. The new TGT can be fetched only when an SSO request is processed. The minimum lifetime that can be specified is 10 minutes. There is no maximum; however, most AD domains have this set to 10 hours (600 minutes), and you should not set the ticket lifetime in SSO configuration above what is specified in AD. The default value is 600 minutes.
I hope this helps!
Seth
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects