Active Directory 2016 PAM feature time-bound group membership

Active Directory 2016 PAM feature time-bound group membership

0 vote

avatar

Hi there,

I think it would be a good PAM improvement to leverage Active Directory's time bound group membership mechanism. Here's an example https://richardjgreen.net/active-directory-2016-time-based-group-membership/
The current PAM solution would lead to a kerberos TGT potentially being valid longer than the actual PAM checkout time. With the time-bound group membership, the kerberos TGT will actually only be valid for the time that you specify.

Cheers
Sebastian

All Comments (1)

avatar

Hello,
It sound interesting. We will read about this and check what we can do.

Regards

David Hervieux