A city IT lead asks why clock skew between workstations and domain controllers matters for Kerberos. What awareness-level answer is most accurate?
Select an answer to reveal the explanation.
Short Explanation
Kerberos tickets come with time windows — like movie tickets that only work for tonight’s show. If the workstation clock and the DC clock disagree wildly, those tickets look expired or not-yet-valid. That is why time sync shows up in AD auth troubleshooting.
Full Explanation
Kerberos relies on synchronized clocks because tickets carry validity intervals that authenticating parties check. Significant skew between clients and domain controllers can cause authentication failures or unexpected ticket behavior. The issue is unrelated to password-length-only checks or DHCP lease mechanics. At assessment and operations awareness depth, ensuring reliable time synchronization is part of healthy Kerberos and Active Directory behavior.