Re: Differences between TGT and Service Tickets



Hi Vilas,

A service ticket is a ticket you need to access a specific service. For normal services, you get your ticket at the KDC and use it to access the service.

But... Requesting that ticket is also accessing a service: the key distributing service at the KDC. For that service, you also need a ticket: the TGT. The name TGT in fact says it all: it's the ticket that will grant you other tickets.

While acquiring the TGT, your password is checked by the AS. For service tickets, only the content of your ticket is checked against the KDC by the service, no further authentication from your side is necessary once the AS has established your identity and granted you the TGT.

Kind regards,

Hans


Tadoori (EXT), Vilas wrote:
Hello All,

I am new to the Kerberos field and would like to know the basic differences between a TGT and a Service Ticket and it would be great if anyone can provide an example on this.


Thanks
Vilas

.



Relevant Pages

  • Re: Perl question
    ... TGT for the realm. ... >> use to try to get a ticket, it will give me the error that the password ... > the attribute set for the 'kadmin/changepw' principal used by kpasswd, ... > impersonator-supplied password as belonging to the victim user). ...
    (comp.protocols.kerberos)
  • Re: 1030 / 40961 / 673 on DC - MVP wanted
    ... You cannot access network resources after you try to log on to a Windows XP ... User-specific Kerberos Ticket-Granting Tickets (TGT) are not renewed. ... Failure Code 0X20 (Ticket Expired?) ...
    (microsoft.public.windows.server.active_directory)
  • Re: Event ID 1030, 40961 and 673 on DC
    ... You cannot access network resources after you try to log on to a Windows XP ... one or more of the following symptoms: ... User-specific Kerberos Ticket-Granting Tickets (TGT) are not renewed. ... Failure Code 0X20 (Ticket Expired?) ...
    (microsoft.public.windows.server.general)
  • Re: Event ID 1030, 40961 and 673 on DC
    ... You cannot access network resources after you try to log on to a Windows XP ... one or more of the following symptoms: ... User-specific Kerberos Ticket-Granting Tickets (TGT) are not renewed. ... Failure Code 0X20 (Ticket Expired?) ...
    (microsoft.public.windowsxp.general)
  • Re: Kerberos v. AD
    ... Microsoft also refer to the TGT as the user ticket and session tickets ... following initial authentication and a session ticket that was provided ... Kerberos plays no part in the authorization process ...
    (microsoft.public.windows.server.active_directory)