Kerberos

A track of P54 · Authentication & Kerberos.

Tickets instead of passwords — the KDC/TGT/service-ticket flow, sealed and time-bounded tickets, replay defence with authenticators, and enterprise SPNs/keytabs/delegation.

An employee arrives in the morning, types one password, and for the rest of the day reaches forty different internal services without typing it again. None of those forty services ever receives the password, and none of them can impersonate the user to the others. If you have only ever built password-per-service authentication, that arrangement sounds like it needs a great deal of trust in a great many places. Kerberos achieves it with surprisingly little, and this track builds the model that makes it work.

The core move is to replace a credential you present with a ticket somebody issued you. You authenticate once to a key distribution centre and receive a ticket-granting ticket, which is not a password but a sealed, time-bounded document. When you want to reach a particular service, you present that ticket to the KDC and receive a service ticket for that one service — encrypted so that only that service can open it, valid for a short window, and useless to anyone else. The password never crosses the wire after the initial exchange, and a compromised service learns nothing that helps it attack a different one.

Two properties deserve attention because they are where the design earns its keep. Time is load-bearing: tickets expire, which is why Kerberos realms are strict about clock skew and why "my clock drifted" is a genuine authentication failure rather than an excuse. And a captured ticket alone must not be enough, so the client sends an authenticator — a freshly encrypted timestamp proving it holds the session key right now — which is what defeats a replayed recording. The track closes on the enterprise reality you will actually meet: service principal names, keytabs, and delegation, where a service acts on a user's behalf and the confused-deputy risk from P56 becomes very concrete.

Authenticateonce, to the KDCTGTa sealed, time-bounded ticketService ticketone service, short windowAuthenticatorfresh proof defeats replay
A ticket you were issued replaces a credential you present, so no service ever sees the password.
Kerberos — TransformerLab