Authorization, Authentication, Accounting Flashcards
RADIUS
Remote Authentication Dial-in User Service
- UDP-based protocol used to communicate with a AAA server
- available on any OS
- RADIUS does not encrypt an entire authentication packet, but only the password
server - runs RADIUS software
RADIUS client - handles requests from supplicants
supplicant - places request
database - may be separate device
TACACS+
Terminal Access Controller Access-Control System Plus
- Cisco proprietary TCP-based AAA protocol
- 3 separate and distinct sessions or functions for authentication, authorization, and accounting
Kerberos
-client/server authentication protocol that supports mutual authentication between a client and a server
-uses the concept of a trusted third party (a key distribution center) that hands out tickets that are used after authenticating one time / SSO
fully encrypted
Local authentication
standard sign in / username and password on local host / device
LDAP
Lightweight Directory Access Protocol
protocol for reading and writing directories over an IP network
X.500 - directory info tree