Kerberos

E191937

Kerberos is a network authentication protocol that uses secret-key cryptography to securely verify the identity of users and services in distributed systems.

All labels observed (18)

How this entity was disambiguated

Statements (49)

Predicate Object
instanceOf authentication protocol
network authentication protocol
security protocol
basedOn symmetric-key cryptography
canUse public-key cryptography extensions
category computer security
commonlyUsedIn Active Directory
Linux systems
linked to: Linux ecosystem

Microsoft Windows domains
UNIX systems
enterprise networks
currentMajorVersion Kerberos version 5
linked to: Kerberos
designedFor client-server model
distributed systems
secure network authentication
developedAt Massachusetts Institute of Technology
developedBy MIT Project Athena
doesNotUse public-key cryptography by default
hasComponent Authentication Server
Key Distribution Center
Ticket Granting Server
linked to: Kerberos
influenced modern single sign-on systems
namedAfter Cerberus from Greek mythology
originallyDevelopedIn 1980s
provides confidentiality
integrity
replay protection
reliesOn shared secret keys
trusted third party
requires synchronized clocks
specifiedIn Kerberos V5 protocol specification
linked to: Kerberos
standardizedAs RFC 4120
standardizedBy IETF
supersededVersion Kerberos version 4
linked to: Kerberos
supports cross-realm authentication
mutual authentication
single sign-on
threatModel eavesdropping
password guessing attacks
replay attacks
transportProtocol TCP
UDP
uses authenticators
secret-key cryptography
session keys
ticket-granting tickets
tickets
time-stamps
usesDefaultPort 88

How these facts were elicited

Referenced by (46)

Full triples — surface form annotated when it differs from this entity's canonical label.

NFS authenticationMechanism Kerberos
SMB authenticationMethod NTLM
linked to: Kerberos
SMB authenticationMethod Kerberos
fetchmail supportsProtocol Kerberos
Thunderbird supportsAuthentication Kerberos
subject linked to: Thunderbird email client
Kerberos hasComponent Ticket Granting Server
linked to: Kerberos
Kerberos currentMajorVersion Kerberos version 5
linked to: Kerberos
Kerberos supersededVersion Kerberos version 4
linked to: Kerberos
Kerberos specifiedIn Kerberos V5 protocol specification
linked to: Kerberos
Samba supportsAuthentication Kerberos
NTLM weakerThan Kerberos
NTLM recommendedReplacedBy Kerberos
MongoDB supportsAuthenticationMechanism Kerberos
subject linked to: MongoDB database
Nix isSmallerThan Kerberos
subject linked to: Nix (moon)
FreeIPA supportsProtocol Kerberos
FreeIPA usesComponent MIT Kerberos
linked to: Kerberos
FreeIPA supportsStandard Kerberos 5
linked to: Kerberos
Key Distribution Center definedIn Kerberos Version 5 specification
linked to: Kerberos
MIT Project Athena notableWork Kerberos authentication protocol
linked to: Kerberos
MIT Project Athena product Kerberos
RFC 4120 title The Kerberos Network Authentication Service (V5)
linked to: Kerberos
RFC 4120 definesProtocol Kerberos Network Authentication Service
linked to: Kerberos
RFC 4120 definesProtocolVersion Kerberos version 5
linked to: Kerberos
RFC 4120 definesComponent Kerberos client
linked to: Kerberos
RFC 4120 definesComponent Kerberos application server
linked to: Kerberos
RFC 4120 definesMessageType KRB-ERROR
linked to: Kerberos
RFC 4120 definesDataFormat Kerberos principal names
linked to: Kerberos
Netatalk supportsAuthenticationMethod Kerberos (via integration)
linked to: Kerberos
MS-NLMP specification relatedTo Kerberos protocol
linked to: Kerberos