143
Chapter 9: Authentication
9.1.9 Idle timeout
Youcanspecifyamountoftimeinminutestheconsoleserverwaitsbeforeitterminatesanidlessh,pmshellorwebconnection.
• SelectSerialandNetwork:Authentication
• WebManagementSessionTimeoutspeciesthebrowserconsolesessionidletimeoutinminutes.Thedefaultsettingis
20 minutes
• CLIManagementSessionTimeoutspeciesthesshconsolesessionidletimeoutinminutes.Thedefaultsettingisto
never expire
• ConsoleServerSessionTimeoutspeciesthepmshellserialconsoleserversessionidletimeoutinminutes.Thedefault
setting is to never expire
9.1.10 Kerberos authentication
TheKerberosauthenticationcanbeusedwithUNIXandWindows(ActiveDirectory)Kerberosservers.Thisformofauthentication
doesnotprovidegroupinformation,soalocaluserwiththesameusernamemustbecreated,andpermissionsset.
Note: Kerberos is very sensitive to time differences between the Key Distribution Center (KDC) authentication server and the
client device. Please make sure that NTP is enabled, and the time zone is set correctly on the console server.
WhenauthenticatingagainstActiveDirectory,theKerberosRealmwillbethedomainname,andtheMasterKDCwillbethe
address of the primary domain controller.
9.1.11 Authentication testing
The Authentication Testing tab enables the connection to the remote authentication server to be tested.