Skip to main content

Kerberos Glossary

abbr.stand for
SPNService Principal Name
UPNUser Principal Name
KDCKey Distribution Center
SPNEGOSimple and Protected GSSAPI Negotiation Mechanism
TGTTicket Granting Ticket
APMAccess Policy Manager
ASAuthentication Server
STService Ticket

ADUC | Active Directory Users and Computers UAC|User Account Control

  • BIG-IP APM
  • APM Session
  • VPE
  • PAC
  • Server <- NTLM Auth -> KDC
  • Client <- Kerberos Auth -> KDC
    • -> AS_REQ
    • <- AS_REP - ticket
    • -> TGS_REQ -> Ticket Granting Server
    • <- TGS_REP - service ticket
    • --> AP_REQ -> Server - service ticket
    • <-- AP_REP <-- Server - UDP, TCP/large ticket
  • SPN - Service Principal Name
  • Delegation - constrained & proxy
    • client --> server --> db
    • tgt --> delegate --> db
  • Protocol Transition
    • validate user
    • kerberos ticket request on user's behalf
      • service for user to self
    • perform constrained delegation

KVNO - Key Version Number

  • Kerberos Pricinple

GSSAPI - Generic Security Services Application Program Interface