Kerberos: tickets, not passwords

P54.kerberos.01 · Audience: guest, it-ml, language-pro · Prerequisites: HMAC, integrity & timing

Real LLM grading for this pageLLM grading (this page):

Kerberos is how enterprise networks authenticate without resending the password on every request: a trusted KDC issues tickets that clients present to services. This track builds a miniature — an HMAC-sealed ticket the KDC issues and a service validates (ties P52), then the authenticator that stops a stolen ticket from being replayed.

Real Kerberos runs over the network against a live KDC; here it's an in-process state machine over the same ideas (no network by design).

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — issue and validate a Kerberos ticket

Loading exercise…

Rung 2 — reject replays with an authenticator

Loading exercise…

My notes on this module

Loading your notes...

Kerberos: tickets, not passwords — TransformerLab