Initial Authentication (PKINIT)
One situation where public key cryptography can benefit the Kerberos protocol is in the initial Authentication Server exchange. Instead of sharing a secret key between the client and KDC, the client possesses a public key pair that is signed by a Certification Authority, which is used to authenticate to the realm.
The key certification method described in the previous section may seem similar to the trusted third party system employed by Kerberos, and, in fact, it is very similar—with one important distinction. The difference is that while both Kerberos and public key certificate authorities employ a trusted third-party model, the trusted third-party is only involved in the public key method when signing the public keys. The rest of the time, the certification authority operates offline; that is, it doesn’t have to be actively involved every time an authentication request is made.
The typical use of PKINIT is to provide each user in the Kerberos realm a signed public key certificate. Each user on their workstation generates a public/private key pair, and the public key is presented to a Certification Authority for validation. Once the key is signed, the certificate is returned to the user and stored on the local hard drive.
The only change to the Kerberos protocol is in the initial Authentication Server message exchange between the authentication client and the KDC. In the traditional symmetric key Kerberos protocol, the client requests a TGT from the ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access