Implement a way to configure different Kerberos ticket lifetimes depending on the authentication method used (password / 2FA / PKINIT). The story here is that 2FA is used to secure more critical systems so not only should getting in be harder (require 2FA), but ticket lifetime should be shorter.
Just for the reference, this topic was discussed by Matt Rogers with MIT in this krbdev thread.
Metadata Update from @pvoborni: - Issue set to the milestone: Future Releases
Fixed by https://pagure.io/freeipa/c/c5f32165d6105a48d9de85a8d29925b58beb9f91
@carbenium thanks for the heads-up.
Closing this ticket as a duplicate of 8001 Need default authentication indicators for SPAKE, PKINIT and encrypted challenge preauth
Metadata Update from @frenaud: - Issue close_status updated to: duplicate - Issue status updated to: Closed (was: Open)