L32
SSO and Kerberos step by step
Cram this first — memory hook
Gate 88 has two ticket-shaped eights: entry ticket, then service ticket. The master ticket is not your password.
Exam trap
A Ticket Granting Ticket is not the ticket handed to every file/printer service. Do not confuse authentication with permission to perform any action.
The slide facts
Single sign-on reuses one login across approved services. Kerberos uses a Key Distribution Center, an initial ticket and service-specific tickets. The bouncer diagram is an analogy, not a literal password-transmission specification.
If you have time — extra
Single Sign-On () is the experience of accessing multiple services without repeatedly logging in. Kerberos is a ticket-based authentication protocol that can provide that experience. The Key Distribution Center () includes an Authentication Service () and Ticket Granting Service (). A Ticket Granting Ticket () lets a client request tickets for specific services without sending the user's password to each service. Tickets are protected and time-limited. In common password-based Kerberos, the password is used locally to derive relevant secret material; do not implement the slide's bouncer analogy as sending a clear password to the . A service ticket authenticates the relationship, while resource authorization still matters. Kerberos commonly uses Transmission Control Protocol /User Datagram Protocol 88. Time synchronization and correct service naming are important dependencies.
Walkthrough
Authenticate to obtain a and associated session material. Use the with the to request a service ticket. Present that ticket and the required proof to the service. The service validates it and applies authorization. Details vary by authentication method and implementation.