Exam - Kerberos - created from Mind Map

Description

Nework Security Note on Exam - Kerberos - created from Mind Map, created by jjanesko on 24/04/2014.
jjanesko
Note by jjanesko, updated more than 1 year ago More Less
jjanesko
Created by jjanesko about 10 years ago
jjanesko
Copied to Note by jjanesko about 10 years ago
87
0

Resource summary

Page 1

principals & their roles A Kerberos principal is a unique identity to which Kerberos can assign tickets. Principals can have an arbitrary number of components: the primary, the instance and the realm. format typically: primary / instance @ realm

applicationsCampus network where access to various resources (printing, file storage (SMB), computing time, proxy authentication, authorisation) needs to be controlled for a population of users, but where the servers do not necessariyl know about (or trust) the users.

weaknesses availability scalability revocation time synchronization reliance TGT lifetime Kerberos has a single point of failure at the authentication server or the ticket granting server. Kerberos systems can only scale to support as much as the central authentication and/ or TGT servers can handle. Ticket granting tickets are good for 10 hours. If a ticket is compromised, there is no mechanism to revoke the ticket. Clocks on the network cannot be more than 5 minutes out of sync for Kerberos to work. The relatively long life and the fixed structure of the TGT opens the door for offline attacks to figure out the encryption key. In Kerberos version 4, the encrpytion algorithm was DES which can be compromised today.

entities authentication server ticekt granting server client server

ahthentication and key exchangeHIGH LEVEL! For exam detail see shared notes!!

Exam - Kerberos

Show full summary Hide full summary

Similar

U2.6 SNMPv3
jjanesko
U2.1 Cables, Hubs, Sniffers
jjanesko
U2.4 LANs, MANs, WANs
jjanesko
U2.5 SNMPv1
jjanesko
U2.1 Cables,Hubs,Sniffers- Thin Ethernet
jjanesko
U2.5 SNMPv1 - architectural model
jjanesko
U2.1 Cables, Hubs, Sniffers - Hub Diagram
jjanesko
U2.2 Switches, ARP - ARP spoofing steps
jjanesko
U2.3 TCP, Routers - Router Diagram
jjanesko
U2.5 SNMPv1 - SNMPv1 protocol stack
jjanesko
U2.2 Switches, ARP
jjanesko