Kerberos Survival GuidePresented by:JD Wade, SharePoint Consultant, MCITPMail: jd.wade@hrizns.comBlog:  http://wadingthrough.wordpress.comLinkedIn: JD WadeTwitter: http://twitter.com/JDWade
AgendaOverview
Logon Process
Accessing a Web Site
Troubleshooting
Kerberos Demos
Delegation and DemosKerberosMassachusetts Institute of Technology
Details Out of ScopeRenewing tickets
Ticket expiration
Keys
Authenticator
TGT Structure
Service Ticket Structure
Encryption/Decryption
Multiple domains/forests
DependenciesSPN
Service Principal NameService ClassHost NamePort
Service Classes allowed by hostalerterhttppolicyagentscmappmgmtiasprotectedstorageseclogonbrowseriisadrasmansnmpcifsminremoteaccessspoolercisvcmessengerreplicatorTapisrv  clipsrvmsiserverrpctimedcommcsvcrpclocatortrksvrdhcpnetdderpcsstrkwksdmservernetddedsmrsvpupsdnsnetlogonsamssw3svcdnscachenetmanscardsvrwinseventlognmagentscesrvwwweventsystemoakleySchedulefaxplugplay
KerberosBenefits
Delegated Authentication
Interoperability
More Efficient Authentication
Mutual AuthenticationLogon Process
KDCAS
KDCAS
KDCTGSASSPN
KDCTGS
Access Web Site
401
SPN
<system.webServer>   <security>      <authentication>         <windowsAuthentication enabled="true" useAppPoolCredentials="true" />      </authentication>   </security></system.webServer>
Troubleshooting
Demos
Delegation
FBAKerberos
ReferencesKen Schaefer’s Multi-Part Kerberos Blog Posts:http://www.adopenstatic.com/cs/blogs/ken/archive/2006/10/20/512.aspx
What Is Kerberos Authentication?http://technet.microsoft.com/en-us/library/cc780469%28WS.10%29.aspx

Kerberos survival guide - SPS Ozarks 2010