SlideShare a Scribd company logo
KDC Clients     Key Distribution Center

                                          Authentication
                         You                  Server

                        HTTP              Ticket Granting
                                              Server
                       service


                               Kerberos Realm

Monday, April 1, 13
Authentication
                      You                           Server

                              plaintext request
                      your ID, Ticket Granting Server ID,
                             IP address, lifetime




Monday, April 1, 13
Authentication
                      You       Server



                               user ID
                            lookup in KDC




Monday, April 1, 13
Authentication
                          You                           Server

                          Ticket Granting Server Session Key
                  HTTP service’s ID, timestamp, lifetime, TGS Session Key



                                Ticket Granting Ticket
                          your ID, HTTP service ID, IP address,
                      timestamp, lifetime, and the TGS Session Key

Monday, April 1, 13
Authentication
                      You                        Server

                      Ticket Granting Server Session Key
                                Your Secret Key



                            Ticket Granting Ticket
                       Ticket Granting Server Secret Key


Monday, April 1, 13
plaintext request
                              HTTP Service ID and lifetime

                                                   Ticket Granting
                           You                         Server

                                   Authenticator
                                your ID and timestamp


                                Ticket Granting Ticket
                          your ID, HTTP service ID, IP address,
                      timestamp, lifetime, and the TGS Session Key

Monday, April 1, 13
Ticket Granting
                      You       Server



                               user ID
                            lookup in KDC




Monday, April 1, 13
plaintext request


                                            Ticket Granting
                      You                       Server

                               Authenticator
                      Ticket Granting Server Session Key


                           Ticket Granting Ticket
                       Ticket Granting Server Secret Key


Monday, April 1, 13
Ticket Granting
                           You                         Server

                               HTTP Service Session Key
                              your client ID and timestamp



                                 Ticket for HTTP Service
                          your ID, HTTP service ID, IP address,
                      timestamp, lifetime, and the TGS Session Key

Monday, April 1, 13
Ticket Granting
                      You                       Server

                          HTTP Service Session Key
                      Ticket Granting Server Session Key


                            Ticket for HTTP Service
                            HTTP Service Secret Key


Monday, April 1, 13
Ticket for HTTP Service
                                your ID, HTTP service ID, IP address,
                       You              timestamp, lifetime,
                                      and the TGS Session Key
                       HTTP
                      service              Authenticator
                                   your client ID and timestamp




Monday, April 1, 13
Ticket for HTTP Service
                                 HTTP Service Secret Key
                       You

                       HTTP
                      service       Authenticator
                                HTTP Service Session Key




Monday, April 1, 13
You
                                       Authenticator
                       HTTP     HTTP service ID and timestamp
                      service




Monday, April 1, 13
You
                                   Authenticator
                       HTTP     HTTP Service Session Key
                      service




Monday, April 1, 13
You

                       HTTP
                      service




Monday, April 1, 13

More Related Content

PPTX
FHIR tutorial - Afternoon
PPTX
kerberos
PPTX
Kerberos
PPTX
Kerberos protocol
PPTX
Kerberos Authentication Protocol
PDF
Cyber Security Standards Update: Version 5 by Scott Mix
PPTX
Kerberos, NTLM and LM-Hash
PPT
Dns protocol design attacks and security
FHIR tutorial - Afternoon
kerberos
Kerberos
Kerberos protocol
Kerberos Authentication Protocol
Cyber Security Standards Update: Version 5 by Scott Mix
Kerberos, NTLM and LM-Hash
Dns protocol design attacks and security

Viewers also liked (10)

PPTX
Phases of penetration testing
PDF
Building Open Source Identity Management with FreeIPA
PPTX
FHIR API for .Net programmers by Mirjam Baltus
PDF
Create FHIR-Enabled Experiences: API-First Approach for Healthcare Apps
PPTX
Getting started with FHIR by Ewout Kramer
PPTX
FHIR Tutorial - Morning
PDF
CNIT 40: 2: DNS Protocol and Architecture
PPTX
HL7 Fhir for Developers
PPTX
PPTX
OpenAM - An Introduction
Phases of penetration testing
Building Open Source Identity Management with FreeIPA
FHIR API for .Net programmers by Mirjam Baltus
Create FHIR-Enabled Experiences: API-First Approach for Healthcare Apps
Getting started with FHIR by Ewout Kramer
FHIR Tutorial - Morning
CNIT 40: 2: DNS Protocol and Architecture
HL7 Fhir for Developers
OpenAM - An Introduction
Ad

Recently uploaded (20)

PDF
Electronic commerce courselecture one. Pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
KodekX | Application Modernization Development
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPTX
Cloud computing and distributed systems.
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
Spectroscopy.pptx food analysis technology
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Electronic commerce courselecture one. Pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
Building Integrated photovoltaic BIPV_UPV.pdf
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Network Security Unit 5.pdf for BCA BBA.
Dropbox Q2 2025 Financial Results & Investor Presentation
KodekX | Application Modernization Development
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Reach Out and Touch Someone: Haptics and Empathic Computing
Cloud computing and distributed systems.
Unlocking AI with Model Context Protocol (MCP)
Per capita expenditure prediction using model stacking based on satellite ima...
Spectroscopy.pptx food analysis technology
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Encapsulation_ Review paper, used for researhc scholars
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Review of recent advances in non-invasive hemoglobin estimation
NewMind AI Weekly Chronicles - August'25 Week I
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Ad

Explain Kerberos like I'm 5

  • 1. KDC Clients Key Distribution Center Authentication You Server HTTP Ticket Granting Server service Kerberos Realm Monday, April 1, 13
  • 2. Authentication You Server plaintext request your ID, Ticket Granting Server ID, IP address, lifetime Monday, April 1, 13
  • 3. Authentication You Server user ID lookup in KDC Monday, April 1, 13
  • 4. Authentication You Server Ticket Granting Server Session Key HTTP service’s ID, timestamp, lifetime, TGS Session Key Ticket Granting Ticket your ID, HTTP service ID, IP address, timestamp, lifetime, and the TGS Session Key Monday, April 1, 13
  • 5. Authentication You Server Ticket Granting Server Session Key Your Secret Key Ticket Granting Ticket Ticket Granting Server Secret Key Monday, April 1, 13
  • 6. plaintext request HTTP Service ID and lifetime Ticket Granting You Server Authenticator your ID and timestamp Ticket Granting Ticket your ID, HTTP service ID, IP address, timestamp, lifetime, and the TGS Session Key Monday, April 1, 13
  • 7. Ticket Granting You Server user ID lookup in KDC Monday, April 1, 13
  • 8. plaintext request Ticket Granting You Server Authenticator Ticket Granting Server Session Key Ticket Granting Ticket Ticket Granting Server Secret Key Monday, April 1, 13
  • 9. Ticket Granting You Server HTTP Service Session Key your client ID and timestamp Ticket for HTTP Service your ID, HTTP service ID, IP address, timestamp, lifetime, and the TGS Session Key Monday, April 1, 13
  • 10. Ticket Granting You Server HTTP Service Session Key Ticket Granting Server Session Key Ticket for HTTP Service HTTP Service Secret Key Monday, April 1, 13
  • 11. Ticket for HTTP Service your ID, HTTP service ID, IP address, You timestamp, lifetime, and the TGS Session Key HTTP service Authenticator your client ID and timestamp Monday, April 1, 13
  • 12. Ticket for HTTP Service HTTP Service Secret Key You HTTP service Authenticator HTTP Service Session Key Monday, April 1, 13
  • 13. You Authenticator HTTP HTTP service ID and timestamp service Monday, April 1, 13
  • 14. You Authenticator HTTP HTTP Service Session Key service Monday, April 1, 13
  • 15. You HTTP service Monday, April 1, 13