Skip to main content
AD Academy
Protocols and Authentication
Intermediate18 minLast updated: Topic 2 of 2

Kerberos — the Ticket System

How a secure sign-in process to a Domain works.

Not read

What you will learn here

  • How ticket-based login works
  • TGT vs Service Ticket
  • Why synchronized clocks matter

Worth reading first:LDAP — the Directory Access Protocol

is the central authentication protocol in modern domains. Instead of sending the password over the network, the user receives Tickets that confirm their identity.

1. הלקוח שולח AS-REQ ל־KDC. 2. ה־KDC מחזיר TGT. 3. הלקוח מבקש כרטיס שירות עם TGS-REQ הכולל SPN. 4. ה־KDC מחזיר כרטיס TGS. 5. הלקוח פונה לשירות עם AP-REQ. 6. השירות מאשר גישה. הסיסמה עצמה לא עוברת ברשת — רק כרטיסים מוצפנים.

Key concepts

  • KDC (Key Distribution Center) — the ticket-issuing center, usually the .
  • (Ticket Granting Ticket) — the initial ticket issued after a successful logon.
  • (Ticket Granting Service) — a ticket for accessing a specific service.
  • (Service Principal Name) — the name by which a service is identified in the .
1. The user enters a password.
2. The KDC issues a TGT.
3. The TGT is used to request a TGS.
4. The TGS is presented to the service — and the user gains access.
text
Architecture and Theory — Under the Hood

is based on tickets, not password transmission. The KDC (every DC) issues a , and with it, the client requests a for each service.

  • AS-REQ/AS-REP — Obtaining a , encrypted with the krbtgt key.
  • TGS-REQ/TGS-REP — Obtaining a ticket for a service, encrypted with the service account password (this is where is born).
  • AP-REQ — Presenting the ticket to the server itself.
  • PAC — Inside the ticket is a list of groups and SIDs — permissions are derived from it.
Practical Configuration (PowerShell / GUI)
klist                     # Display tickets
klist purge               # Delete tickets (refresh permissions)
setspn -L svc_sql         # SPN of service account
w32tm /query /status      # Clock synchronization
bash
Troubleshooting
  • Falling back to instead of — almost always a missing or duplicate .
  • setspn -X shows duplicate SPNs — duplication breaks authentication for both accounts.
  • Accessing via IP instead of FQDN forces .
Glossary and Quick Command Line
  • — Primary ticket, valid for 10 hours.
  • — Ticket for a specific service.
  • krbtgt — The account whose key encrypts all TGTs ().

Check yourself

What is a TGT in Kerberos?

Was this page helpful?