[18861] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: TGS-REP TICKET decrypting problem

daemon@ATHENA.MIT.EDU (somenath saha)
Fri Jun 13 10:34:57 2014

MIME-Version: 1.0
In-Reply-To: <0B2317B2-D1C1-4AFC-923C-F70F07759C79@oracle.com>
Date: Fri, 13 Jun 2014 11:36:28 +0530
Message-ID: <CAKSryKVUKgmV7suwo-j030f_9qEvCzA2WPVxCms4+ib_bKL5FQ@mail.gmail.com>
From: somenath saha <saha.somenath.88@gmail.com>
To: Wang Weijun <weijun.wang@oracle.com>
Content-Type: multipart/mixed; boundary=14dae93d93807810cc04fbb17a9b
Cc: Danilo Almeida <dalmeida@mit.edu>, "krbdev@mit.edu" <krbdev@mit.edu>
Errors-To: krbdev-bounces@mit.edu

--14dae93d93807810cc04fbb17a9b
Content-Type: text/plain; charset=UTF-8

hi wang,

is it right?
Let there are two client CLIENT-1 and Clinet-2. now suppose CLIENT-1 get an
ticket from KDC in TGS_REP message as he want to communicate with CLIENT-2.
now CLIENT-1 forward this ticket to CLIENT-2 in AP_REQ message. now
CLIENT-2 must have right to decrypt the ticket to get the shared key..  am
i right???

check the attached image and confirm me i'm right or not.




On Fri, Jun 13, 2014 at 11:10 AM, Wang Weijun <weijun.wang@oracle.com>
wrote:

> The service ticket is meant to be read by the service. The client should
> not be able to decrypt it.
>
> --Max
>
> On Jun 13, 2014, at 13:11, somenath saha <saha.somenath.88@gmail.com>
> wrote:
>
> > hi wang,
> >
> > yes i can create keytab file and grab the necessary key from there. but
> it is not my intention. i don't want to take any help from KDC as i want to
> write separate code for client. why should client take the key from KDC.
> client have to prepare it and must decrypt the ticket..
> >
> >
> > On Fri, Jun 13, 2014 at 10:36 AM, Wang Weijun <weijun.wang@oracle.com>
> wrote:
> > Didn't you already created a keytab file using esedbexport and
> dskeytab.py? Inside it there is one key that should decrypt the service
> ticket.
> >
> > --Max
> >
> > On Jun 13, 2014, at 13:00, somenath saha <saha.somenath.88@gmail.com>
> wrote:
> >
> > > hi danilo and other
> > >
> > > I forgot to mention something about my setup.  I am running an Active
> Directory domain on a Windows Server 2012 machine with two Windows (windows
> server 2012) clients joined to the domain. In windows server 2012 i create
> a user "krbtest" and password of this user is "Krbtest2012". now i prepare
> a key using the user credential i.e username "krbtest " , its password and
> corresponding domain and enctype. Using this key i can decrypt the AS_REP
> message. but i can't decrypt the TGS_REP ticket using that key. please help
> me out and inform me if you need any other details..
> > >
> > >
> > > On Thu, Jun 12, 2014 at 11:59 AM, somenath saha <
> saha.somenath.88@gmail.com> wrote:
> > > Danilo,
> > >
> >
> >
>
>

--14dae93d93807810cc04fbb17a9b
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

--14dae93d93807810cc04fbb17a9b--

home help back first fref pref prev next nref lref last post