Application Server and KDC share some information like Service Tkt key?

Surendra Babu A surendra.a at samsung.com
Wed Dec 28 01:16:33 EST 2005


Hi Douglas,

Could you please clarify the following issue? I am working on Kerberos
Server Authentication feature and using the Windows 2000 Exchange server as
the KDc server and SMTP server as the Application server.

My aim: Server authentication should be done.

Clarification on "Service Ticket Key":

http://www.xml-dev.com/blog/index.php?action=viewtopic&id=21
In the above link, the 4th and 5th steps are little confusing for me.

1. In the 3rd step, KDC sends the Service Tkt encrypted with the "Service
Tkt Key". and etc.

2. In the 4th step, Client sends the  same Service Tkt key and authenticator
to the Application server. That means, the KDC and Application server should
agree on one "Service Ticket key". That means, there should be some
communication between KDC and Application server. Right? How to configure
the same with the Application server? Could you please let me know the same?

Thank you,
-Surendra




More information about the Kerberos mailing list