UCF STIG Viewer Logo

The Kerberos policy option Maximum lifetime for user ticket renewal must be configured for a maximum of 7 days or less.


Overview

Finding ID Version Rule ID IA Controls Severity
V-2379 AD.4032_2003 SV-28500r1_rule ECSC-1 Medium
Description
This setting determines the period of time (in days) during which a users TGT may be renewed. This security configuration limits the amount of time an attacker has to crack the TGT and gain access.
STIG Date
Win2k3 Audit 2013-06-10

Details

Check Text ( None )
None
Fix Text (F-5784r1_fix)
Configure the Kerberos policy option "Maximum lifetime for user ticket renewal" to a maximum of 7 days or less.