SLIDE 15 Overview Background Our solution Conclusions Authentication mechanisms Web services
Kerberos operation
KEYas−tgs
+ TGT: [KEYclient−tgs] [KEYclient−tgs, clientID,...]
passwd KEYtgs−serv
[KEYclient−serv]
KEYclient−tgs
+ ST: [KEYclient−serv, clientID,...]
1
(user+passwd) Login
User Client Application (serv) Server
KDC
AS
TGT
3 2
Request TGT KEYtgs−serv KEYas−tgs KEYtgs−serv KEYas−tgs
3) The client requests a Service Ticket (ST), presenting the TGT as credential to the Ticket Granting Server (TGS)
Esteban Talavera González Credential Mapping in Grids 12