Differences between TGT and Service Tickets

Hans van Zijst hans at woefdram.nl
Thu Dec 10 08:33:36 EST 2009


Hi Vilas,

A service ticket is a ticket you need to access a specific service. For 
normal services, you get your ticket at the KDC and use it to access the 
service.

But... Requesting that ticket is also accessing a service: the key 
distributing service at the KDC. For that service, you also need a 
ticket: the TGT. The name TGT in fact says it all: it's the ticket that 
will grant you other tickets.

While acquiring the TGT, your password is checked by the AS. For service 
tickets, only the content of your ticket is checked against the KDC by 
the service, no further authentication from your side is necessary once 
the AS has established your identity and granted you the TGT.

Kind regards,

Hans


Tadoori (EXT), Vilas wrote:
> Hello All,
> 
> I am new to the Kerberos field and would like to know the basic differences between a TGT and a Service Ticket and it would be great if anyone can provide an example on this.
> 
> 
> Thanks
> Vilas
> 



More information about the Kerberos mailing list