Domain 5: Identity and Access Management (IAM)

Video transcripts

Every course video in Domain 5, written out with timestamps so you can search the wording instead of scrubbing through playback.

  • Transcript

    1. 0:00Doctor Elena Rivera is back at work
    2. 0:03accessing shared research resources hosted by Eastbrook Institute,
    3. 0:07but this time
    4. 0:08there's a layer of security in place that protects both universities.
    5. 0:12Cerberus,
    6. 0:14named after the mythological guard dog of the underworld,
    7. 0:17Kerberus secures digital realms using three key elements authentication,
    8. 0:22authorization,
    9. 0:23and auditing.
    10. 0:24It's a network authentication protocol that uses
    11. 0:27secret key cryptography to establish trusted communication.
    12. 0:31Here's how it works.
    13. 0:33There are 3 main participants
    14. 0:35the principal in this case,
    15. 0:37Doctor Rivera's laptop,
    16. 0:39the application server,
    17. 0:41Eastbrook's research portal,
    18. 0:43the key distribution center,
    19. 0:45or KDC.
    20. 0:46The central authority that verifies and issues digital tickets.
    21. 0:50The KDC performs two jobs first as the authentication server
    22. 0:55and then as the ticket granting server or TGS.
    23. 0:58Doctor Rivera logs in using her university credentials.
    24. 1:02Her system sends a request to the authentication server at Redwood Valley's KDC.
    25. 1:08The authentication server checks her identity against its records.
    26. 1:12Once verified,
    27. 1:13it sends back a ticket granting ticket or TGT.
    28. 1:17This ticket granting ticket is proof that she has authenticated,
    29. 1:21much like holding a passport,
    30. 1:23but she still needs permission to enter the Eastbrook portal.
    31. 1:26Doctor Rivera's system sends the ticket granting
    32. 1:29ticket to the ticket granting server,
    33. 1:31still part of the key distribution center.
    34. 1:34The ticket granting server verifies it and issues a service ticket
    35. 1:38this time specifically for the Eastbrook Research server.
    36. 1:41Now,
    37. 1:42Doctor Rivera presents this service ticket to the server
    38. 1:46because the server and key distribution center trust each other,
    39. 1:49access is granted.
    40. 1:51Tickets are stored in a secure area of her device's memory.
    41. 1:55Kerberri does not require her to re-enter her password.
    42. 1:59The session lasts for a set time,
    43. 2:01usually about 8 to 10 hours,
    44. 2:03after which she must reauthenticate.
    45. 2:06To prevent misuse,
    46. 2:07Kerbers relies heavily on accurate time synchronization.
    47. 2:11Even a few minutes of clock drift can cause login failures.
    48. 2:15Cerberus ensures users are who they say they are.
    49. 2:18Once authenticated,
    50. 2:20they can securely access multiple services
    51. 2:22without exposing their passwords again.
    52. 2:25However,
    53. 2:26Cerberus has its limits.
    54. 2:28It depends on passwords for encryption,
    55. 2:30so weak credentials can be exploited.
    56. 2:33The key distribution center must also be kept
    57. 2:36secure and should never serve other functions.
    58. 2:39If it goes offline and there's no backup,
    59. 2:41access fails.
    60. 2:43Cerberus doesn't protect the contents of communication.
    61. 2:46Other tools like IPSEC are needed for that.
    62. 2:49But when it comes to verifying identities and controlling access,
    63. 2:53it provides a powerful framework for secure collaboration between institutions
    64. 2:57like Redwood Valley University and Eastbrook Institute of Technology.
    Open in the ISC2 portal