Auditing
The final A in the three As is auditing . Auditing takes the results from authentication and authorization and records these results into an audit log. The audit log records all actions taken by the authentication and authorization steps for future review by an administrator. While authentication and authorization are preventative systems in which unauthorized access is prevented, auditing is a reactive system. Auditing will not prevent an attacker from gaining access to your network; instead, it will give you a detailed log of when, where, and how the attacker penetrated your systems.
All Kerberos implementations we will cover have the ability to log events that take place during authentication requests. We’ll take a very close look at auditing in Chapter 6, where we’ll review what logging can be enabled in the various Kerberos implementations and how to view those logs.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access