authentication Flashcards

1
Q

Kerberos

A

port 88

    • ticket granting system
  • mutual authentication (client & server)
  • no need to re-authenticate (SSO)

–> protection vs. man-in-the-middle / replay attacks

! domain controller can be a single point of failure –> mitigation: primary and secondary domain controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

RADIUS

A
  • udp 1812 (auth), 1813 (accounting)
  • open standard, AAA server
  • used for VPN concentrators

does not support remote access protocol, NetBIOS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

TACAS+

A
  • port 49 (tcp, more reliable but a bit slower than radius)

Cisco proprietary for N administration, supports all N protocols

provides separate authentication and authorisation functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

LDAP

A

L7 prot for accessing directory services data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

RADIUS vs TACACS+

A

RADIUS TACACS+
open standard Cisco only
network access & wifi device administration
UDP 1812/1813 TCP 49
Auth & authorisation are combined A / A / A are separated - more granular control
only pass is encrypted (username is plaintext) // everything is encrypted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly