OSF DCE Application Development Guide--Core Components

DCE Security Service
Figure 23-2. Client Acquires Ticket-Granting Ticket Using Third-Party Protocol
Login: principalname
password
Privilege Service
Registry Service
Authentication Service
API layer
sec_login_setup_
identity(principalname..
sec_login_valid_and
cert_ident(password..
User Interface
Legend:
conversation key 1
mtgt host machine TGTmachine session key
request TGT for client
corresponding to
principalname
mtgt
TS
user’s secret key
conversation key 2
TS
TS
mtgt
TS
TGT
client’s TGT
TS
rpc
rpc
if status=OK, then get PTGT
from PS (Privilege Service)
Security runtime
Security Server
Client Principal
mtgt
TS timestamp
secval Process
TGT
TGT
TGTTGT
TGT
PS conversation key
mtgt
238 Tandem Computers Incorporated 124245