> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/es/active-directory/kerberos/general-kerberos-flow.md).

# Flujo general de Kerberos

### Paso 1 — AS-REQ

Cuando un usuario inicia sesión, su cliente envía una consulta al KDC:

```bash
AS-REQ
```

Esta consulta corresponde a la consulta de autenticación inicial.

### Paso 2 — AS-REP

Si la autenticación es válida, el KDC devuelve una respuesta:

```bash
AS-REP
```

Esta respuesta contiene notablemente un **TGT**o **Ticket Granting Ticket**.

El TGT puede verse como un ticket general que le permite solicitar tickets de servicio.

### Paso 3 - TGS-REQ

Cuando el usuario quiere acceder a un recurso, por ejemplo un recurso compartido de red, presenta su TGT al KDC.

El cliente entonces envía:

```bash
TGS-REQ
```

Esta solicitud consulta un ticket para un servicio específico.

### Paso 4 — TGS-REP

El KDC verifica el TGT y devuelve un ticket de servicio:

```bash
TGS-REP
```

Este ticket es específico del servicio solicitado.

### Paso 5 — Acceso al recurso

El cliente presenta el ticket de servicio al servidor de destino.

Por ejemplo, para acceder a:

```bash
//WS01/C$
```

El cliente envía un ticket de servicio al servidor `WS01`.

Si el ticket es válido pero el usuario no tiene los permisos necesarios en el recurso compartido, la autenticación puede tener éxito, pero el acceso SMB será denegado.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/es/active-directory/kerberos/general-kerberos-flow.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
