• Users should be able to change their password without
inconveniencing anyone else. However, with Kerberos, a change in
a principal's master DES key or a change in the KDC's master DES
key would affect tickets held by other users.
• Therefore, each key has a version number. Network resources
(including the KDC) should remember several versions of their own
key. Since tickets expire in about 21 hours, there is no reason to
remember a superseded key any longer than that.
• In tickets and other protocol messages, the key version number is
sent, so that it can be known which key to use.