• proteldxp破解版下载 > 的网络安全性)
  • 的网络安全性)

    免费下载 下载该文档 文档格式:PPT   更新时间:2002-09-05   下载次数:0   点击次数:1
    文档基本属性
    文档语言:
    文档格式:ppt
    文档作者:Steve Riley
    关键词:
    主题:TechEd 2002
    备注:Formatted: Dionne Miller, Silver Fox
    点击这里显示更多文档属性
    Msg
    Msg: the user name
    the challenge
    the response
    DC: domain controller
    SAM (Security Account Manager Database)
    Microsoft NTLM (Cont.)
    NTLM non-interactive authentication:
    Step 0: A user accesses a client machine and provides a domain name, user name, and password. The client computes a cryptographic hash of the password and discards the actual password. (Interactive authentication only)
    Step 1: The client sends the user name to the server (in plaintext).
    Step 2: The server generates a 16-byte random number, called a challenge or nonce, and sends it to the client.
    Microsoft NTLM (Cont.)
    NTLM non-interactive authentication:
    Step 3: The client encrypts this challenge with the hash of the user's password and returns the result to the server. This is called the response.
    Step 4: The server sends the following three items to the domain controller: the user name, the challenge sent to the client, and the response received from the client.
    Microsoft NTLM (Cont.)
    NTLM non-interactive authentication:
    Step 5: The domain controller uses the user name to retrieve the hash of the user's password from the Security Account Manager database. It uses this password hash to encrypt the challenge.
    Step 6: The domain controller compares the encrypted challenge it computed (in step 5) to the response computed by the client (in step 3). If they are identical, authentication is successful.
    Microsoft NTLM (Cont.)
    No mutual authentication: server authenticates the client, but not vice versa. (没有相互验证:server 验证 client, client 无法验证 server.)
    Microsoft Kerberos
    Mutual authentication: server authenticates client, and client authenticates server. (相互验证:server 验证 client, client 验证 server.)
    Microsoft Kerberos (Cont.)
    Authenticator Message
    Session Key
    Session Key
    Client
    Server
    Microsoft Kerberos (Cont.)
    Kerberos (or Cerberus) was a figure in classical Greek mythology—a fierce, three-headed dog who kept living intruders from entering the Underworld. (Kerberos: 希腊神话中的三头怪物)

    上一页下一页

  • 下载地址 (推荐使用迅雷下载地址,速度快,支持断点续传)
  • 免费下载 PPT格式下载
  • 您可能感兴趣的
  • proteldxp2004下载  proteldxp  proteldxp注册机  proteldxp2004安装  proteldxp2004中文版  proteldxp2004教程  如何安装proteldxp  proteldxp教程  proteldxp安装