Re: Keytab, service and contacts with the KDC/AD

"Henry B (Hank) Hotz, CISSP" <[email protected]> Sat, 6 Oct 2018 17:58:51 -0700
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Message-ID <[email protected]>
Not to beat a dead horse, but yes. That=E2=80=99s actually a pretty good =
description of what happens.

Good luck.

> On Oct 4, 2018, at 9:11 AM, Ken Hornstein <[email protected]> =
wrote:
>=20
>> Since the service ticket contains the session key encrypted with the
>> service key, and the service knows its key via the keytab file, the
>> service is able to decrypt the ticket, get the session key, decrypt =
the
>> remaining part of the authenticator, and compare the identity =
encrypted
>> with the session key with the identity embedded in the ticket =
service,
>> enabling it to authenticate the client.
>>=20
>> All of this without the service contacting the KDC. That is the most
>> important point.
>>=20
>> Am I right ?
>=20
> Yes.
>=20
> --Ken

Personal email.  [email protected]