Ńň Ă#xPc @ sđ d d k l Z d d k l Z l Z d d k Td d k l Z e d Z h d d 6d d 6Z d e f d YZ e i e d e f d YZ e i e d e f d YZ e i e d e f d YZ e i e d S( i˙˙˙˙( t api( t Intt Str( t *( t _s Kerberos ticket policy There is a single Kerberos ticket policy. This policy defines the maximum ticket lifetime and the maximum renewal age, the period during which the ticket is renewable. You can also create a per-user ticket policy by specifying the user login. For changes to the global policy to take effect, restarting the KDC service is required, which can be achieved using: service krb5kdc restart Changes to per-user policies take effect immediately for newly requested tickets (e.g. when the user next runs kinit). EXAMPLES: Display the current Kerberos ticket policy: ipa krbtpolicy-show Reset the policy to the default: ipa krbtpolicy-reset Modify the policy to 8 hours max life, 1-day max renewal: ipa krbtpolicy-mod --maxlife=28800 --maxrenew=86400 Display effective Kerberos ticket policy for user 'admin': ipa krbtpolicy-show admin Reset per-user policy for user 'admin': ipa krbtpolicy-reset admin Modify per-user policy for user 'admin': ipa krbtpolicy-mod admin --maxlife=3600 iQ t krbmaxticketlifei: t krbmaxrenewableaget krbtpolicyc B sř e Z d Z e d e i i f d Z e d Z d d g Z d g Z e d Z e d Z e d d d d e d d e d d e e d d d d e d d e d d d e d d d d e d d e d d d f Z d Z RS( s' Kerberos Ticket Policy object t cnt kerbeross kerberos ticket policy settingsR R t krbticketpolicyauxs Kerberos Ticket Policys uid?t cli_namet usert labels User namet docs&