KERBEROS  AUTHENTICATION  PROCESSBYAjinkyaPatil
Authentication Process1. Request TGTAS2. TGT Key distribution centerTGS3. Request Service Ticket4. Service Ticket Sent5. Service Ticket PresentedCLIENT MACHINESERVICE SERVER6. Telnet Communication Channel
Step I (Request TGT)Client enters the credentials User ID and Password
Client Machine performs a Hash Function on PASSWORD.
Client sends User ID to the AS (Authentication Server) in clear-text.Step II (TGT sent)AS creates the Hash of PASSWORD (SECRET KEY).
AS sends  2 messages to client machine:
Message A:
Message B:Step II continuedTGT encrypted using TGS secret key.
TGS sends Message A & B to Client.
Client Machine is able to decrypt the Messages A only if SECRET KEY (password) is correct.
Client machine has Client/ TGS session Key.
Client cannot decrypt the Message B.Step III (Service Ticket Request)Message C: (Message B & service ID)
Message D:

Kerberos