[18814] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: TGS-REP TICKET decrypting problem

daemon@ATHENA.MIT.EDU (somenath saha)
Wed Jun 11 00:54:16 2014

MIME-Version: 1.0
In-Reply-To: <33E2E06D4C33464A97D0F4884B2543061416B813@OC11EXPO25.exchange.mit.edu>
Date: Wed, 11 Jun 2014 10:23:48 +0530
Message-ID: <CAKSryKWUYRQuUuUxhbdM_No4Ji9X8da_Q3d0Epfkjt9WCFb7OA@mail.gmail.com>
From: somenath saha <saha.somenath.88@gmail.com>
To: Danilo Almeida <dalmeida@mit.edu>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

HI all,

I have three machine. one is used as windows server 2012 where KDC is
running and also DHCP and DNS is running there. and other two pc is
connected with this server. Now two client pc want to communicate with each
other using cifsv2.  Before that they must be authenticate by kerberos.
everything goes fine. The problem is arise where 2nd client pc want to
decrypt the ticket which he recived from 1st client pc through AP-REQ
message. I think 2nd client pc must not communicate again with kdc to get
his secret key to decrypt the pc. It should be know to him but i'm unable
to prepare the key as i don't know which credential is used to prepare the
key. please go through the firs mail in this mail chain to find out the
user Account credential for 2nd pc. The ticket is encrypted with
aes256-cts-hmac-sha1-96 algorithm.

regards
somenath


On Wed, Jun 11, 2014 at 3:50 AM, Danilo Almeida <dalmeida@mit.edu> wrote:

> Somenath,
>
> What is your end-to-end scenario?
>
> - Danilo
>
>
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post