First of all sorry for my bad English.
I dont know where to ask these questions so i chose this group for posting
them. I have a little homework about active directory and its kerberos
authentication protocol. So i need some real answers.
1)Why kdc sends the tgt before the session key with tickect for requested
service?
Whats wrong if kdc sends the ticket, encrypted with clients password?
2) What should client do if it wants to change its password?
Also what should application server do if it wants to change its key?
3) If we want to add a new service to kdc, what should we do?
4) Is there anything speacial needs to do while the connection between
client and service server is ending?
I will be very happy if someone answers my questions or shows me a link
which includes detailed information about kerberos.
I require real answers, i need to know whats going on behind

Thank you...