A method and system for maintaining a secure association between a client
and a server in a distributed computing system by computing a session
identifier as a function of a Kerberos-based authentication ticket. The
session identifier is independently derived or verified by the client and
the server upon a first request by the client to the server, and each
subsequent request by the client to the server is tagged with this session
identifier to provide a reliable security association.