How can I change the ticket lifetime used by Kerberos?

John Savill

April 6, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

A. The default lifetime for a Kerberos ticket is defined by the grouppolicy for the domain which is 10 hours by default. It can be changed as followsbut 10 hours will normally suffice (unless people work very long days):

  1. Start the Active Directory Users and Computers MMC snap-in (Start - Programs - Administrative Tools - Active Directory Users and Computers)

  2. Right click on the domain and select Properties from the context menu

  3. Select the 'Group Policy' tab

  4. Select the domain group policy object and click Edit

  5. Expand the Computer Configuration root then Weindows Settings - Security Settings - Kerberos Policy

  6. Double click the time you wish to change, modify and click OK
    Click here to view image

  7. Close the group policy editor

To force the GPO change to take effect you can run

C:> secedit /refreshpolicy machine_policy /enforce

About the Author

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like