When a user enters a user name and password,
the computer sends the user name to the KDC. The KDC contains a master database
of unique long term keys for every principal in its realm. The KDC looks up the
user's master key (KA), which is based on the user's password. The KDC then
creates two items: a session key (SA) to share with the user and a
Ticket-Granting Ticket (TGT). The TGT includes a second copy of the SA, the
user name, and an expiration time. The KDC encrypts this ticket by using its
own master key (KKDC), which only the KDC knows. The client computer receives
the information from the KDC and runs the user's password through a one-way
hashing function, which converts the password into the user's KA. The client
computer now has a session key and a TGT so that it can securely communicate
with the KDC. The client is now authenticated to the domain and is ready to
access other resources in the domain by using the Kerberos protocol.
0 comments:
Post a Comment