What Does Kerberos Support Mean?
There are essentially two “types” of Kerberos support that a client/server application can implement. The first, and unfortunately, most common is for the client to send the server the user’s Kerberos password in plain text. The server then acquires a TGT on the user’s behalf (and hopefully verifies that the TGT is valid by also acquiring a service ticket for itself—see the description of the man-in-the-middle attack in Chapter 6 for details on why this is important). This method has a distinct advantage: most protocols that require authentication only support simple, plain text username and password authentication. Even if the protocol is extensible enough to support stronger authentication methods, these stronger authentication methods are usually not widely supported by the variety of clients in use. This method, of course, has the disadvantage of sending the user’s credentials in plain text over the network. Since Kerberos is designed as a single-sign-on solution, exposure of a user’s credentials in this way is even more dangerous since the same username and password is accepted for authentication by other Kerberos-enabled services. Finally, this method does not allow for a true single-sign-on solution; instead, it provides users with a single login and password that they have to enter multiple times.
The other method of supporting Kerberos authentication is what I’ll call “native” Kerberos authentication support. Native Kerberos authentication ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access