Skip to content

Kerberos Protocol

Kerberos is a network authentication protocol designed to provide secure, passwordless authentication over insecure networks. It relies on symmetric key cryptography and a trusted third-party infrastructure called the Key Distribution Center (KDC) to manage credentials and issue tickets. This section explains the core mechanics of Kerberos, including the Ticket Granting Ticket (TGT), service tickets, and the KDC’s role in the authentication process.


Overview of Kerberos Authentication

Kerberos operates on a three-party model: 1. Client: The user or system requesting access to a service. 2. Server: The service (e.g., a file server, database) the client wants to access. 3. KDC: The trusted authority that issues tickets. The KDC is logically split into two components: - Authentication Server (AS): Issues the initial Ticket Granting Ticket (TGT). - Ticket Granting Server (TGS): Issues service tickets after verifying the TGT.

The protocol ensures confidentiality, integrity, and mutual authentication by using time-stamped tickets encrypted with shared secrets.


Authentication Flow

  1. Client to AS (Authentication Request)
    The client requests a TGT by sending its username and a timestamp to the AS.

    kinit <username>
    
    The AS verifies the client’s credentials (e.g., against Active Directory) and issues a TGT encrypted with the client’s password hash.

  2. Client to TGS (Service Ticket Request)
    The client sends the TGT to the TGS along with a request for a service ticket (e.g., for ldap/dc01.example.com). The TGS decrypts the TGT, verifies the client’s identity, and issues a service ticket encrypted with the service’s key.

  3. Client to Service (Service Ticket Presentation)
    The client presents the service ticket to the target service. The service decrypts it using its key, validates the ticket, and grants access.


Ticket Granting Ticket (TGT)

  • Purpose: Acts as a temporary credential to request service tickets without re-entering the password.
  • Encryption: Encrypted with the client’s password hash (stored in Active Directory).
  • Lifetime: Typically 10 hours (configurable), after which the TGT expires.

Example:

# List active Kerberos tickets
klist


Service Tickets

  • Purpose: Allow the client to access a specific service (e.g., HTTP/web01.example.com) without re-authenticating.
  • Encryption: Encrypted with the service’s key (stored in Active Directory).
  • Lifetime: Shorter than TGTs (e.g., 1 hour), reducing the risk of misuse.

Example:

# Request a service ticket for a specific service
kinit <username> -p <service_principal>


Key Distribution Center (KDC)

  • Role: Manages the issuance and validation of tickets. The KDC must be trusted by all clients and services.
  • Security Considerations:
  • The KDC’s private keys must be protected (e.g., via hardware security modules).
  • Misconfiguration (e.g., incorrect realm settings) can lead to authentication failures or vulnerabilities.

Key takeaways

  • Kerberos uses symmetric encryption and tickets to avoid transmitting passwords over the network.
  • The TGT enables passwordless access to services via service tickets.
  • The KDC (split into AS and TGS) is critical for credential validation and ticket issuance.
  • Proper configuration and protection of KDC keys are essential to prevent exploitation.
  • Tools like kinit and klist are used to manage Kerberos tickets in practice.