2.2 Flashcards
TACACS+
Terminal Access Control Access Control System Plus. An AAA protocol developed by Cisco that often authenticates to admin accounts for network appliance management
RADIUS
Remote Authentication Dial In User Service. An AAA protocol used to manage remote and wireless authentication infrastructures. Mainly for wireless and VPN access.
Kerberos
Single sign on authentication and authorization service based on a time sensitive, ticket granting system.
SAE
Simultaneous Authentication of Equals. A personal authentication mechanism for WiFi networks introduced with WPA3 (WiFi protected access 3) to address vulnerabilities in WPA-PSK (WiFi protected access pre shared key) method. SAE is not an enterprise solution
TKIP
Temporal Key Integrity Protocol. A mechanism used in the first 5 versions of WPA (WiFi protected access) to improve wireless encryption mechanisms’ security compared to the flawed WEP (wired equivalent privacy) standard
AES
Advanced Encryption Standard. A symmetric 128-, 192-, or 256- bit block cipher used for bulk encryption in modern security standards such as WPA2, WPA3, and TLS (Transport Layer Security). Not for enterprise solutions
CCMP
Computer Mode with Cipher Block Chaining Message Authentication Code Protocol.An encryption protocol used for wireless local area networks (WLANs) that addresses the vulnerabilities of the WEP (Wired Equivalent Privacy) protocol.
EAP
Extensible Authentication Protocol. Allows different mechanisms to authenticate against a network directory. This protocol would be the foundation of managing WiFi access based on Active Directory user objects.
WEP
Wired Equivalent Privacy. Legacy security algorithm for personal 802.11 wireless networks that is highly vulnerable to attacks.
WPA2
WiFi Protected Access 2. Uses AES (Advanced Encryption Standard) cipher deployed within CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol). AES replaces RC4 and CCMP replaces TKIP
WPA3
WiFi Protected Access 3. Next gen wireless data security intended to replace WPA2 by using AES Galois Counter Mode Protocol (GCMP) mode of operation.
Shared Secret
A Shared Secret allows the RAIDUS server and access point to trust one another.
RC4
Rivest Cipher 4. Used exclusively with WEP, but is no longer used from a security perspective. Also used in WPA1 in conjunction with TKIP.