SUBSCRIBE to Windows IT Pro Magazine & SAVE 30%     Register today for your FREE 'To The Point' SharePoint eNewsletter
     
     
Skip Navigation Links.
Collapse Office and SharePointOffice and SharePoint
Expand Newsletter ArchivesNewsletter Archives
Expand Office 2007Office 2007
Expand Office 2003Office 2003
Collapse SharePointSharePoint
Expand Installation and DeploymentInstallation and Deployment
SharePoint Extends a Nonprofit’s Reach
How to change your personal information in MOSS 2007
KPI's in Microsoft Office SharePoint Server 2007
Expand Integrating SharePoint and Microsoft Office 2003Integrating SharePoint and Microsoft Office 2003
Diving Into the Windows SharePoint Services 3.0 API
Hide custom list items
Linking to documents in another document library
Custom Web Part Basics
Expand Integrating SharePoint and Microsoft Office 2007Integrating SharePoint and Microsoft Office 2007
Testing Our Web Part Base Class
Expand Working OfflineWorking Offline
Installing Microsoft's Application Templates
Manage quick menu item using EditControlBlock in WSS 3.0
Expand Windows SharePoint Services Document LibrariesWindows SharePoint Services Document Libraries
Creating and Using a New Column Type
Corporate Blogging
SharePoint 2007 Content Types
Windows SharePoint Services Out of the Box
More About SharePoint 2007 Content Types
Using Content Types in Windows SharePoint Services 3.0
SQL storage planning & monitoring (MS white paper)
Display the user name for the logged on user
Outlook 2007 and SharePoint Synchronization
Use Kerberos to Secure MOSS 2007
10 Important Kerberos Facts
Stsadm
SSRS and MOSS 2007
Shared Tasks Lists with SharePoint and Outlook 2007
Introducing the Business Data Catalog
Information Integration: SSRS and MOSS 2007
What Can I Accomplish with Other SharePoint Technologies?
Integrate SharePoint into Your Exchange Environment
Outlook and SharePoint: Playing Well Together
SharePoint Integration with Outlook 2007, Part 3
Bridge the SharePoint File-Restore Gap
Migration Glitch in SharePoint Portal Server
Windows SharePoint Services 3.0 Out of the Box
SharePoint Security Evolution
Creating and Using a New Content Type in SharePoint 2007
Announcements
     

     

     
     

10 Important Kerberos Facts

You should read this list of Kerberos facts if you read nothing else in this article. Kerberos is an important protocol that’s sometimes misunderstood by administrators.

1. Kerberos is an industry standard that was initially developed by MIT in the 1980’s. The current version, Kerberos 5, is defined in RFC 1510.
2. If you log on to an Active Directory (AD) domain from a computer running Windows 2000 or later, you are probably relying on the Kerberos 5 authentication protocol to access a wide array of network resources, such as AD domain resources, file shares, print services, Microsoft IIS, and even resources protected by IPSec.
3. Kerberos is currently the most secure authentication mechanism supported by AD.
4. Kerberos is the best choice for most Microsoft Office SharePoint Server 2007 (MOSS) implementations in an intranet or extranet where users log on to an AD domain.
5. Kerberos is the only Windows authentication protocol that provides constrained delegation (aka double-hop authentication) and protocol transition.
6. Windows Integrated Authentication is a superset of the authentication protocols Kerberos and NTLM.
7. Kerberos Digest and Basic authentication (augmented for security with TLS/SSL) protocols aren’t part of Windows Integrated Authentication but are available via the Security Support Provider Interface (SSPI) in Windows.
8. Kerberos authentication to a Web site requires that your Microsoft browser be Microsoft Internet Explorer 5.0 or above. Mozilla Firefox and other browsers also support Kerberos authentication.
9. Kerberos works for both password-based and smart card-enabled authentication.
10. In Greek mythology, Kerberos/Cerberus was the Greek god, Hades’, watchdog-a threeheaded canine that guarded the gates of the underworld.