Kerberos
- Pronunciation
- KUR-ber-ross
In short
Kerberos is a network authentication protocol in which a trusted server issues time-limited tickets, so users prove who they are without sending passwords.
What is Kerberos?
Kerberos was created at MIT in the 1980s, and its current version, Kerberos 5, is defined in RFC 4120. It lets users and services on a network prove their identity to each other through a trusted third party, the Key Distribution Center (KDC). The name comes from Cerberus, the three-headed guard dog of Greek myth, after the three parties involved: the client, the server and the KDC.
When you log in, your computer proves to the KDC that you know your password, without sending the password itself, and receives a ticket-granting ticket (TGT). Whenever you then open a file share, an intranet site or a database, your computer shows the TGT to the KDC and gets a service ticket for that one server, which the server checks with its own secret key. Tickets are encrypted with symmetric keys, carry timestamps and expire after a set time, 10 hours by default in Active Directory.
It works like a theme park: you show your ID once at the main gate and get a day pass, then trade the day pass for a ticket at each ride, and no ride operator ever sees your ID. This is why employees on a Windows domain sign in once in the morning and open internal servers all day without typing their password again. Microsoft Active Directory has used Kerberos as its default sign-in protocol since Windows 2000, and it is also common in Linux and Unix networks.
Kerberos is often confused with LDAP because Active Directory uses both. Kerberos answers "who are you?" by issuing tickets, while LDAP is the protocol for reading the directory, such as a user's email address and group memberships. Kerberos also differs from SAML and OpenID Connect: it works best inside a company network, while those standards bring single sign-on to web and cloud apps through the browser.
Key takeaways
- Kerberos authenticates users and services with tickets from a trusted KDC.
- Passwords never travel over the network, and tickets expire after a few hours.
- A ticket-granting ticket gets service tickets for each server without a new login.
- Active Directory uses Kerberos for sign-in and LDAP for directory lookups.
- Clocks must stay in sync, by default within 5 minutes.
Example
# Log in to the realm: asks for the password once and caches a TGT
kinit alice@EXAMPLE.COM
# List cached tickets: the TGT, plus a service ticket for each server used
klist
# Open an intranet page with a Kerberos ticket instead of a password (SPNEGO)
curl --negotiate -u : https://intranet.example.com/reports
# Log out: delete the cached tickets
kdestroyReaders ask
What is the difference between Kerberos and LDAP?
Kerberos proves identity: it checks who you are once and issues tickets for services. LDAP reads and updates directory data such as users, groups and email addresses. Active Directory combines them, signing users in with Kerberos and looking up who they are and which groups they belong to with LDAP.
What is a ticket-granting ticket?
The ticket-granting ticket (TGT) is the first ticket the KDC issues when you log in. Your computer presents it to get service tickets for individual servers, so you don't type your password again until the TGT expires.
Why does Kerberos fail when clocks are out of sync?
Tickets and the messages that use them carry timestamps, so an attacker can't replay old ones. By default, a message more than 5 minutes off is rejected, which is why machines in a Kerberos realm synchronize their clocks.
See also
- AuthenticationSecurity, p. 3Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- SSOSecurity, p. 48SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
- LDAPSecurity, p. 25LDAP is an open protocol for searching and updating a directory service, the central database of an organization's users, groups and devices.
- SAMLSecurity, p. 42SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
- Symmetric EncryptionSecurity, p. 51Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
- Zero TrustSecurity, p. 56Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
Sources
Spotted a mistake or something missing on this page?Suggest an edit