Figure 46.1 YaST: Basic Configuration of a Kerberos Client
To configure ticket-related options in the Advanced Settings dialog, choose from the
following options:
• Specify the Default Ticket Lifetime and the Default Renewable Lifetime in days,
hours, or minutes (using the units of measurement d, h, and m, with no blank space
between the value and the unit).
• To forward your complete identity to use your tickets on other hosts, select For-
wardable.
• Enable the transfer of certain tickets by selecting Proxiable.
• Keep tickets available with a PAM module even after a session has ended by en-
abling Retained.
• Enable Kerberos authentication support for your OpenSSH client by selecting the
corresponding check box. The client then uses Kerberos tickets to authenticate with
the SSH server.
• Exclude a range of user accounts from using Kerberos authentication by providing
a value for the Minimum UID that a user of this feature must have. For instance,
you may want to exclude the system administrator (root).
854
Installation and Administration