Case BEE679 · Identity & AD · L2 Practitioner
How Kerberos Authentication Works
Practise as: Explain it · Interview
Interview questionWalk me through what happens on the wire when a domain user opens a file share.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- AS-REQ/AS-REP: user proves key (pre-auth timestamp) to KDC and gets a TGT encrypted with the krbtgt account key
- TGS-REQ/TGS-REP: user presents TGT, gets a service ticket encrypted with the target service account key
- AP-REQ: client sends the service ticket to the server, which decrypts it with its own key; the KDC is not contacted
- PAC inside tickets carries group SIDs used for authorization; time skew over 5 minutes breaks auth by default
- Events: 4768 (TGT requested), 4769 (service ticket requested), 4771 (pre-auth failed) on domain controllers
If the interviewer pushes back
- Why does the service not validate the PAC with the KDC by default, and what attack does that enable?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.