OSF DCE Application Development Guide--Core Components
DCE Security Service
Figure 23-2. Client Acquires Ticket-Granting Ticket Using Third-Party Protocol
Login: principalname
password
Privilege Service
Registry Service
Authentication Service
API layer
sec_login_setup_
identity(principalname..
sec_login_valid_and
cert_ident(password..
User Interface
Legend:
conversation key 1
mtgt host machine TGTmachine session key
request TGT for client
corresponding to
principalname
mtgt
TS
user’s secret key
conversation key 2
TS
TS
mtgt
TS
TGT
client’s TGT
TS
rpc
rpc
if status=OK, then get PTGT
from PS (Privilege Service)
Security runtime
Security Server
Client Principal
mtgt
TS timestamp
secval Process
TGT
TGT
TGTTGT
TGT
PS conversation key
mtgt
23−8 Tandem Computers Incorporated 124245