Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up

Kerberos V5 & Active Directory Authentication Studio

Architect enterprise SSO and identity infrastructure: trace 3-phase ticket exchanges, inspect Privilege Attribute Certificate (PAC) signatures, and audit defenses against Kerberoasting.

AES-256-CTS-HMAC-SHA1-96 KDC Signatures Valid
10.0 Hours
TGT Maximum Validity Window
± 300 sec
Allowed Timestamp Skew Limit (Replay Guard)
14 SIDs
Embedded PAC Security Group Identifiers
Low (gMSA Active)
Kerberoasting Vulnerability Posture

1. Realm & Service Principal Name (SPN) Configuration

2. Complete Kerberos V5 Protocol Ticket Flow

Phase 1: Authentication Service Exchange (AS-REQ → AS-REP)
Client → KDC: AS-REQ { client: alice@CORP.COM, pre-auth: Enc(timestamp, K_alice) }
KDC → Client: AS-REP { TGT: Enc({ alice, session_key_1, PAC }, K_krbtgt), Enc(session_key_1, K_alice) }
Phase 2: Ticket Granting Service Exchange (TGS-REQ → TGS-REP)
Client → KDC: TGS-REQ { TGT, Authenticator: Enc(timestamp, session_key_1), SPN: MSSQLSvc/... }
KDC → Client: TGS-REP { ServiceTicket: Enc({ alice, session_key_2, PAC }, K_service), Enc(session_key_2, session_key_1) }
Phase 3: Application Client-Server Exchange (AP-REQ → AP-REP)
Client → Server: AP-REQ { ServiceTicket, Authenticator: Enc(timestamp, session_key_2) }
Server → Client: AP-REP (Mutual Authentication verified. Authorization granted via validated PAC SIDs).
Click "Run Kerberoasting Audit" to inspect offline cracking resistance for the configured SPN.

3. Production krb5.conf & Active Directory Hardening

// Generated krb5.conf
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement