Approval Configuration
Different duration presets can be configured for the Vault approvals process in Kron PAM. The following parameter can be defined in the System Config Manager, and approval times are given in minutes, hours, days, and infinite:
Parameter Name | Parameter Value | Description |
|---|---|---|
sapm.approved.account.expiration.time.value | 30m,2h,5d ,-1 (“-1” means infinite) | This parameter defines the approval expiration time. |
The sapm.approved.account.expiration.time.values parameter is structurally connected to the sapm.show.password.expiration.time.values parameter. For example, if an account has received 2 hours of approval, password checkout durations exceeding 2 hours are not shown. Since it is set parametrically, the sapm.approved.account.expiration.time.values and sapm.show.password.expiration.time.values parameters must always work synchronously.