Kerberos Survival GuidePresented by:JD WadeSenior SharePoint Consultant, MCTS, MCITPMail: jd.wade@hrizns.comBlog:  http://wadingthrough.comLinkedIn: JD WadeTwitter: http://twitter.com/JDWade
Who is JD Wade?SharePoint Consultant since 2007
Certified KnowledgeLake Partner
With Horizons since 2005
Member of SharePoint 2007 and 2010 TAP
Over 10 years of IT experience
Technical Editor for book SharePoint 2010 Disaster Recovery http://tinyurl.com/SPDRBook2010
Loves anything related to sound
Probably has one of the driest senses of humor in the roomAgendaOverview
Logon Process
Accessing a Web Site
Troubleshooting Kerberos
DelegationKerberosMassachusetts Institute of Technology
Details Out of ScopeRenewing tickets
Ticket expiration
Keys
Authenticator
TGT Structure
Service Ticket Structure
Encryption/Decryption
Multiple domains/forests
DependenciesSPN
Service Principal NameService ClassHost NamePortHTTP/website:80
Service Classes allowed by hostalerterhttppolicyagentscmappmgmtiasprotectedstorageseclogonbrowseriisadrasmansnmpcifsminremoteaccessspoolercisvcmessengerreplicatorTapisrv  clipsrvmsiserverrpctimedcommcsvcrpclocatortrksvrdhcpnetdderpcsstrkwksdmservernetddedsmrsvpupsdnsnetlogonsamssw3svcdnscachenetmanscardsvrwinseventlognmagentscesrvwwweventsystemoakleySchedulefaxplugplay
KerberosBenefits
Delegated Authentication
Interoperability
More Efficient Authentication
Mutual Authentication
IIS – Chatty by default
IIS6 – See MS KB 917557
IIS7 – See MS KB 958473Logon Process
KDC
KDC
KDCSPN
KDC
Access Web Site
401
SPN
<system.webServer>   <security>      <authentication>         <windowsAuthentication enabled="true" useAppPoolCredentials="true" />      </authentication>   </security></system.webServer>
TroubleshootingKerberos
ToolsKnowledge
SetSPN
Windows Security Logs

Kerberos survival guide SPS Kansas City