Re: Keytab, service and contacts with the KDC/AD
"Henry B (Hank) Hotz, CISSP" <[email protected]> Sat, 6 Oct 2018 17:58:51 -0700
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <[email protected]> |
Not to beat a dead horse, but yes. That=E2=80=99s actually a pretty good = description of what happens. Good luck. > On Oct 4, 2018, at 9:11 AM, Ken Hornstein <[email protected]> = wrote: >=20 >> Since the service ticket contains the session key encrypted with the >> service key, and the service knows its key via the keytab file, the >> service is able to decrypt the ticket, get the session key, decrypt = the >> remaining part of the authenticator, and compare the identity = encrypted >> with the session key with the identity embedded in the ticket = service, >> enabling it to authenticate the client. >>=20 >> All of this without the service contacting the KDC. That is the most >> important point. >>=20 >> Am I right ? >=20 > Yes. >=20 > --Ken Personal email. [email protected]