4.1 Flashcards
RADIUS
-More common AAA protocol.
-centralize authentication
-requires additional encryption to secure data during authentication process.
*AAA through RADIUS uses Server secret key (a shared secret key). A key mismatch could cause log in problems.
TACACS+
-require additional encryption to secure data during authentication process
LDAP
-Uses TCP/IP
-Used in windows AD
-Used to query and update x.500 directory
-container and leaf objects
Kerberos
-authenticate once, trusted
-client and server authenticates with each other
-uses cryptographic tickets
-can be used over insecure networks while using strong encryption to protect data.
802.1x
Port based NAC
EAP integrates with 802.1x
Used in conjunction with access database (radius, TACACS, ldap)
EAP
Extensible Authentication Protocol
-Authentication framework
-Many different ways to authenticate
-Manufacturers can build their own EAP methods