Kerberos
Kerberos
NTLM
-Vulnerable to what
NTLM
New Technology LAN Manager
-Message digest hashing algorithm to challenge users and check credentials
-Confidentiality, integrity, authentication
-Windows
-Somewhat insecure
-Vulnerable to pass the hash attacks (use someone else’s password hash to log in)
-Use Kerberos instead
LDAP
-Port
Windows active directory domains and linux realms
RADIUS
RADIUS
Diameter
Diameter
CHAP
CHAP
MS-CHAP
MS-CHAP
PAP
PAP
TACACS+
TACACS+
OAuth
OAuth
NAC
NAC
Network Access Control
-Inspect clients to ensure healthy
-user or system authentication
-802.1x is a form of NAC
-Encryption of traffic to the wireless and wired network using protocols for 802.1X such as EAP-TLS, EAP-PEAP or EAP-MSCHAP
-Often tied to Role-based Access. Access to the network will be given according to the profile of the person and the results of a posture/health check.
Uses a challenge message during authentication
-Three answers
Uses a challenge message during authentication
Directory Services
-What technology to implement?
Directory Services
RADIUS Federation
RADIUS Federation