How can I change the ticket lifetime used by Kerberos?
April 6, 2000
A. The default lifetime for a Kerberos ticket is defined by the grouppolicy for the domain which is 10 hours by default. It can be changed as followsbut 10 hours will normally suffice (unless people work very long days):
Start the Active Directory Users and Computers MMC snap-in (Start - Programs - Administrative Tools - Active Directory Users and Computers)
Right click on the domain and select Properties from the context menu
Select the 'Group Policy' tab
Select the domain group policy object and click Edit
Expand the Computer Configuration root then Weindows Settings - Security Settings - Kerberos Policy
Double click the time you wish to change, modify and click OK
Click here to view imageClose the group policy editor
To force the GPO change to take effect you can run
C:> secedit /refreshpolicy machine_policy /enforce
About the Author
You May Also Like