Salesforce

KB-6050: How to configure a group for automatic Kerberos Credentials for infinite renewal?

« Go Back

Information

 
TitleKB-6050: How to configure a group for automatic Kerberos Credentials for infinite renewal?
URL NameKB-6050-How-to-configure-a-group-for-automatic-Kerberos-Credentials-for-infinite-renewal
Knowledge Article TypeHow To’s
Article TypeKnowledge
ArticleType 
ProductAuthentication Service
ComponentUNIX/Linux Agent
Version5.4.3; 5.4.2; 5.4.1; 5.4.0; 5.3.1; 5.3.0; 5.2.3
Tagskerberos, infinite renewal, batch groups
Internal Comments
Article Edits
Bug #75989
Solution ID
Knowledge Base Article Details
Question:

How to configure a group for automatic Kerberos Credentials for infinite renewal?
 
Answer:

Starting DirectControl 5.2.3 [Centrify Server 2015.1 release] Centrify Administrator can specify groups whose members’ Kerberos credentials require infinite renewal even after the group members have logged out.
 
Example usage:
1. Edit centrifydc.conf
2. krb5.cache.infinite.renewal.batch.groups: test_group_sam@example.com
3. Restart DirectControl Agent (adclient) or run adreload to apply the latest configuration

Option Explanation:
Use this configuration parameter in centrifydc.conf to specify a list of Active Directory groups whose members’ Kerberos credentials require infinite renewal even after the users have logged out. Groups that you specify must be Active Directory groups, but do not need to be zone enabled. However, only zone enabled users in a group will have their credentials automatically renewed.

You must use the following format to specify group names:
SamAccountName@domain

By default, this parameter does not list any groups. If a user is removed from the group the keytab file generated will be removed the next time adreload is ran or adclient is restarted. 

For users please review:
KB-6044: How to configure users for automatic Kerberos Credentials for infinite renewal even after users have logged out?

For more information, please see attach Centrify Hadoop Guide
Created ByGary Wong
Solution CreatorShin Fong
DraftNot Checked
LithiumId
Lithium_Board_Id
Lithium_View_Href
Tags 
Category 
ArticleImage
Known IssuesNot Checked

Powered by