How Kerberos works



  • Every user and service that participates in the Kerberos authentication protocol requires a principal to uniquely identify itself.
  • there are user principals and service principals
  • eg:- alice@EXAMPLE.COM


  • an authentication administrative domain

Key distribution center (KDC):

  • The KDC ()  is comprised of three components:
  • the Kerberos database, the authentication service (AS),
  • and the ticket-granting service (TGS).
  • eg:- – The KDC for the Kerberos realm EXAMPLE.COM

Kerberos WORKFLOW:-

Aim: User needs to access the Service identified by myservice/

  • User initiates a request to the AS at, (identifying himself as the principal xyz@EXAMPLE.COM)
  • AS responds by providing a TGT that is encrypted using the key (password) for the principal
  • User is now prompted to enter the correct password for the principal in order to decrypt the message
  • User now uses TGT and requests a service ticket from the TGS at
  • TGS validates the TGT and provides user a service ticket, encrypted with the myservice/ principal’s key
  • User now presents the service ticket to myservice, which can then decrypt it using the myservice/ key and validate the ticket.

About shalishvj : My Experience with BigData

6+ years of experience using Bigdata technologies in Architect, Developer and Administrator roles for various clients. • Experience using Hortonworks, Cloudera, AWS distributions. • Cloudera Certified Developer for Hadoop. • Cloudera Certified Administrator for Hadoop. • Spark Certification from Big Data Spark Foundations. • SCJP, OCWCD. • Experience in setting up Hadoop clusters in PROD, DR, UAT , DEV environments.
This entry was posted in Security and tagged , , , . Bookmark the permalink.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s