UCF STIG Viewer Logo

The Kerberos policy user ticket renewal maximum lifetime must be limited to 7 days or less.


Overview

Finding ID Version Rule ID IA Controls Severity
V-2379 WN12-AC-000013-DC SV-51166r2_rule ECSC-1 Medium
Description
This setting determines the period of time (in days) during which a user's TGT may be renewed. This security configuration limits the amount of time an attacker has to crack the TGT and gain access.
STIG Date
Windows Server 2012/2012 R2 Domain Controller Security Technical Implementation Guide 2017-04-28

Details

Check Text ( None )
None
Fix Text (F-44324r1_fix)
Configure the policy value in the Default Domain Policy for Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Account Policies -> Kerberos Policy -> "Maximum lifetime for user ticket renewal" to a maximum of 7 days or less.