Identity & Access Management Flashcards
EAP
Extensible Authentication Protocol
Integrates with 802.1X
Framework commonly used for wireless networks ; EAP-TLS, LEAP , EAP-TTLS, PEAP.
CHAP
Challenge Handshake Authentication Protocol.
Uses an encrypted challenge and three-way handshake to send credentials
-Challenge message
-Password hash from challenge and password
-Server compares hash
802.1X
IEEE standard for network access control (port based NAC)
RADIUS, LDAP, TACACS+
Supplicant - the client
Authenticator- go between provides access
Server - validates credentials
What is RADIUS?
Remote Authentication Dial-in User Service
Operates via TCP or UDP
sends passwords that are obfuscated by a shared secret and MD5 hash.
Typically encrypted using IPSec
TACACS+
Terminal Access Controller Access Control System
Cisco designed, uses TCP for AAA providing full packet encryption and granular command controls
Kerberos
Favoured by Microsoft: Operates on untrusted networks and uses authentication to shield its traffic.
The primary - username
The instance - to differentiate similar primaries
The realm - groups of users separated by trust boundaries.
TGT
Ticket Granting Ticket
When I client wants to use Kerberos to access a service they request this; (authentication ticket)
TGS
Ticket Granting Service (Kerberos)
KDC
Kerberos Distribution Centre
SAML
Security Assertion Markup Language
XML based open standard for exchanging AA information between identity and service providers
LDAP
Lightweight Directory Access Protocol
Deployed as part of an identity management infrastructure database to offer hierarchically organised directory
MFA
Multi Factor Authentication
-something you know
-something you have
-something you are
- somewhere you are
- something you can do
- something you exhibit
- someone you know
TOTP
Time-based One Time Passwords
Use algorithm to drive a password using current time as part of the process, and is valid for set period
eg Google Authenticator
HMAC
Hash Based Message Authentication Code
HOTP
HMAC based One Time Password
(Hash Based Authentication Code)
FRR
False Rejection Rate