Received: from SOUTH-STATION-ANNEX.MIT.EDU by po7.MIT.EDU (5.61/4.7) id AA10018; Tue, 5 Dec 95 17:05:36 EST
Received: from poblano.near.net by MIT.EDU with SMTP
	id AA15260; Tue, 5 Dec 95 15:32:46 EST
Date: Tue, 5 Dec 95 15:32:46 EST
From: MAILER-DAEMON@MIT.EDU (Mail Delivery Subsystem)
Subject: Returned mail: Deferred: Connection timed out during user open with mercury.telecheck.com
Message-Id: <9512052032.AA15260@MIT.EDU>
To: owner-kerberos@MIT.EDU

   ----- Transcript of session follows -----
451 kerberos@uc.msc.edu... reply: read error
451 kerberos@uc.msc.edu... reply: read error
451 uk-kerberos@doc.ic.ac.uk... reply: read error
451 uk-kerberos@doc.ic.ac.uk... reply: read error
421 cygnus.com.tcp... Deferred: Connection refused by cygnus.com
421 gardenia.saclay.cea.fr.tcp... Deferred: Connection timed out during user open with oeillet.saclay.cea.fr
451 tt@virginia.edu... reply: read error
451 tt@virginia.edu... reply: read error
451 kerberos@po.cwru.edu... reply: read error
451 kerberos@po.cwru.edu... reply: read error
>>> RCPT To:<DJMSYS@ritvax.isc.rit.edu>
<<< 553 unknown or illegal user: DJMSYS@ritvax.isc.rit.edu
550 DJMSYS@ritvax.isc.rit.edu... User unknown
451 w-rolph@ds.mc.ti.com... reply: read error
451 w-rolph@ds.mc.ti.com... reply: read error
421 vix.com.tcp... Deferred: Connection timed out during user open with gw.home.vix.com
421 rce.com.tcp... Deferred: Connection timed out during user open with gw.home.vix.com
451 zgj16234@foreigner.class.udg.mx... reply: read error
451 zgj16234@foreigner.class.udg.mx... reply: read error
421 telecheck.com.tcp... Deferred: Connection timed out during user open with mercury.telecheck.com

   ----- Unsent message follows -----
Received: from poblano.near.net by MIT.EDU with SMTP
	id AA14721; Tue, 5 Dec 95 15:32:46 EST
Received: from jon.bbnplanet.com by poblano.bbnplanet.com id aa21710;
          5 Dec 95 13:11 EST
X-Sender: jon@poblano.near.net (Unverified)
X-Mailer: Windows Eudora Pro Version 2.1.2
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Date: Tue, 05 Dec 1995 13:12:17 -0500
To: Richard Basch <basch@lehman.com>,
        "Alessandro Aldini mat.1193" <aldini@zeus.csr.unibo.it>
From: Jon Rochlis <jon@bbnplanet.com>
Subject: Re: Help about Kerberos (TGT request)
Cc: kerberos@MIT.EDU
Message-Id:  <9512051311.aa21710@poblano.bbnplanet.com>


What Richard wrote is correct but I don't think it answers Alessandro's
question.

If the question is
        how does the KDC get its knowledge of a client's secret key in the
first place?

the answer is an administrator tells the KDC what it is when the user's
kerberos principal is created. This either takes place at the console of the
KDC or via an encrypted admin protocol (based on the administrator's key).

The password string to DES key process is simply a convenience for the user.
The KDC only deals with password as user registration/password change time.

                -- Jon


