Friday, July 10, 2020

Kerberos

Kerberos is named after 3-headed dog in Greek mythology.

It is a single sign on protocol to provide authentication service on network.


It is a must study protocol for CISSP exam and it is almost guaranteed topic with quiet a few questions about the protocol, mainly in Domain 5: Identity and Access Management (IAM)

Secure LDAP

LDAP by default is not really secure.

Default ports are 389 & 3268 - 3268 is for Global Catalog.

A common alternative method of securing LDAP communication is using an SSL tunnel. 

The default port for LDAP over SSL is 636.

Global Catalog is available by default on ports 3268, and 3269 for LDAPS.