> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/de/active-directory/kerberos/general-kerberos-flow.md).

# Allgemeiner Kerberos-Ablauf

### Schritt 1 — AS-REQ

Wenn sich ein Benutzer anmeldet, sendet sein Client eine Anfrage an den KDC:

```bash
AS-REQ
```

Diese Anfrage entspricht der ersten Authentifizierungsanfrage.

### Schritt 2 — AS-REP

Wenn die Authentifizierung gültig ist, gibt der KDC eine Antwort zurück:

```bash
AS-REP
```

Diese Antwort enthält insbesondere ein **TGT**oder **Ticket-Granting-Ticket**.

Das TGT kann als allgemeines Ticket betrachtet werden, mit dem Sie Service-Tickets anfordern können.

### Schritt 3 - TGS-REQ

Wenn der Benutzer auf eine Ressource zugreifen möchte, zum Beispiel eine Netzwerkfreigabe, legt er dem KDC sein TGT vor.

Der Client sendet dann:

```bash
TGS-REQ
```

Diese Anfrage fordert ein Ticket für einen bestimmten Dienst an.

### Schritt 4 — TGS-REP

Der KDC überprüft das TGT und gibt ein Service-Ticket zurück:

```bash
TGS-REP
```

Dieses Ticket ist speziell für den angeforderten Dienst.

### Schritt 5 — Zugriff auf die Ressource

Der Client legt dem Zielserver das Service-Ticket vor.

Zum Beispiel für den Zugriff auf:

```bash
//WS01/C$
```

Der Client übermittelt dem Server ein Service-Ticket `WS01`.

Wenn das Ticket gültig ist, der Benutzer jedoch nicht über die erforderlichen Berechtigungen für die Freigabe verfügt, kann die Authentifizierung erfolgreich sein, der SMB-Zugriff wird jedoch verweigert.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/de/active-directory/kerberos/general-kerberos-flow.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
