Zum Hauptinhalt springen
Glossary

Kerberos

Updated on 1 min

Kerberos is a network authentication protocol based on a ticket system. A central Key Distribution Center (KDC) issues time-limited tickets after successful authentication, allowing the user to access various services without re-entering their password. Kerberos forms the foundation of authentication in Microsoft Active Directory. For your ISMS, Kerberos is relevant because misconfigurations such as overly long ticket lifetimes or weak encryption algorithms enable attacks like Kerberoasting. Monitor the Kerberos configuration of your domain controllers and ensure that current encryption standards (AES-256) are in use.