Week 3 Flashcards
Three A’s of security
Authentication, authorization, accounting
Identification
Idea of describing an entity uniquely
Example: your email address
What must an org do to issue client certificates?
Must set up and maintain CA infrastructure to issue and sign certificates
Certificate revocation list
A signed list published by the CA which defines certificates that have been explicitly revoked
RADIUS
A protocol that provides AAA services for users on a network
Kerberos
A network authentication protocol that uses “tickets” to allow entities to prove their identity over potentially insecure channels to provide mutual authentication
TACACS+
Primarily used for device administration, authentication, authorization, and accounting
What is an example of a service that uses single sign on authentication?
Kerberos
Authorization
Pertains to what the user accountants access to, or doesn’t have access to
OAuth
An open standard that allows users to grant third party websites and applications access to their information without sharing account credentials
Access Control List
A way of defining permissions or authorizations for objects
Accounting
Keeping records of what resources and services your users accessed, or what they did when they were using your systems