[18778] in Kerberos_V5_Development
Re: TGS-REP TICKET decrypting problem
daemon@ATHENA.MIT.EDU (Wang Weijun)
Tue May 20 05:59:29 2014
Mime-Version: 1.0 (Mac OS X Mail 7.2 \(1874\))
From: Wang Weijun <weijun.wang@oracle.com>
In-Reply-To: <CAKSryKUWsBJTP9Mz=w3nZ3Qgu1cObgE=dMN4WsKfew9pwhR97w@mail.gmail.com>
Date: Tue, 20 May 2014 17:55:28 +0800
Message-Id: <4AB98018-D14F-4E50-92CA-D279AF307518@oracle.com>
To: somenath saha <saha.somenath.88@gmail.com>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="windows-1252"
Errors-To: krbdev-bounces@mit.edu
Content-Transfer-Encoding: 8bit
The KDC is using the secret key of the computer itself, which is not the same as any of those user accounts. Assuming your KDC is a Windows Server, you will see "Users and Computers" in the Active Directory Domain Services manager, which means each user and computer is a different principal.
--Max
On May 20, 2014, at 17:09, somenath saha <saha.somenath.88@gmail.com> wrote:
> Hi,
>
> I need some information regarding the ticket creation in KDC.
>
> Assume my pc’s host name is “SOMENATH-PC” & it has 3 user accounts.
> They are:
>
>
>
> *USER NAME PASSWORD*
>
> i) Administrator administrator
>
> ii) Somenath somenath
>
> iii) Guest guest
>
>
>
> Now in TGS_REQ message I send “*cifs/SOMENATH-PC.xyz.com
> <http://somenath-pc.xyz.com/>” *as server name (Service & Host) in
> KDC_REQ_BODY. After receiving TGS_REQ message KDC prepare a ticket which is
> encrypted by using server’s secret key i.e. SOMENATH-PC’s secret key.
>
>
>
> Now my question is that in order to encrypt the enc-part of the ticket what
> credential’s is used by KDC as *“SOMENATH-PC”* has three user accounts
> which is mentioned above. Please provide me some information regarding my
> question.
>
>
>
> Regards,
>
> Somenath
>
>
> On Thu, May 15, 2014 at 12:56 PM, somenath saha
> <saha.somenath.88@gmail.com>wrote:
>
>> Hi,
>>
>> I need some information regarding the ticket creation in KDC.
>>
>> Assume my pc’s host name is “SOMENATH-PC” & it has 3 user accounts.
>> They are:
>>
>>
>>
>> *USER NAME PASSWORD *
>>
>> i) Administrator administrator
>>
>> ii) Somenath somenath
>>
>> iii) Guest guest
>>
>>
>>
>> Now in TGS_REQ message I send “*cifs/SOMENATH-PC.xyz.com
>> <http://SOMENATH-PC.xyz.com>” *as server name (Service & Host) in
>> KDC_REQ_BODY. After receiving TGS_REQ message KDC prepare a ticket which is
>> encrypted by using server’s secret key i.e. SOMENATH-PC’s secret key.
>>
>>
>>
>> Now my question is that in order to encrypt the enc-part of the ticket
>> what credential’s is used by KDC as *“SOMENATH-PC”* has three user
>> accounts which is mentioned above. Please provide me some information
>> regarding my question.
>>
>>
>>
>> Regards,
>>
>> Somenath
>>
> _______________________________________________
> krbdev mailing list krbdev@mit.edu
> https://mailman.mit.edu/mailman/listinfo/krbdev
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev