Hi All ,

Can a windows service long term key be changed on the fly? 


What I mean is when the machine hosting service joins the domain
long term keys are exchanged between service and KDC ( This is what
I understand . Please correct me If I am not ).

If as a KDC admin I would like to change the key being used for
encrypting service tickets for the service , Is there a way to do it ?

If I somehow change the key for given SPN ( using ktpass ) on KDC
is it possible to communicate this back to service ?Does KDC do it
automatically ?Is there some event it waits for before syncing keys with
service ?


Thanks

Nikhil
________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos

Reply via email to