[22205] in Kerberos

home help back first fref pref prev next nref lref last post

Re: keytab vs database

daemon@ATHENA.MIT.EDU (Luke Howard)
Tue Aug 17 08:36:53 2004

From: Luke Howard <lukeh@padl.com>
Message-Id: <200408171234.WAA85855@au.padl.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
To: m1r4cle_26@yahoo.com
Date: Tue, 17 Aug 2004 22:34:07 +1000
cc: kerberos@mit.edu
Reply-To: lukeh@padl.com
Errors-To: kerberos-bounces@mit.edu


>I have a basic question about kerberos concept.
>As I browsed through MIT source code to better
>understand how kerberos works, I noticed that in
>processing the tgs request, the ticket is always
>decrypted using server's key retrieved from keytab. If
>the server is a TGS service (krbtgt) or
>kadmin/changepw which are part of a KDC (am I right to
>say this ?), is it okay to retrieve the key from the
>database instead of from the keytab ? 

Yes, and I believe this is what Heimdal does. Not sure about MIT.


-- Luke

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post