Master NTLM & Kerberos Authentication: The 2 Crucial Protocols

Active Directory, Networking, Q&A, SOC
Table of Contents

Introduction to NTLM and Kerberos Authentication: What is NTLM?

NTLM is a Microsoft Windows authentication protocol. It is a challenge-response authentication protocol that uses the MD4 hash function.

 

NTLM is designed to provide strong security, but it can be vulnerable to man-in-the-middle and replay attacks.

 

The NTLM protocol was developed by Microsoft in 1993 for use with the NT family of operating systems. The original name of the protocol was LanMan, but it was later changed to NTLM since this was a more descriptive name for what it does.

NTLM Authentication

NTLM is an authentication protocol in Windows Active Directory. NTLM uses an encrypted challenge-response authentication process to authenticate a user without sending its password over. We know that passwords are stored in Doman Controller in Active Directory.

 

First, the client sends an authentication request called NTLM Negotiate with user details. The Server replies with the NTLM Challenge (a 16-byte number). This number is encrypted with the hashed value of the client’s passwords. The server since it stores the passwords, it itself encrypts the challenge with the user password has and compares it with the response. If the values match, the user is authenticated.

NTLM Authentication
NTLM Authentication

NTLM as a Password-Based Protocol vs. Kerberos Authentication

NTLM is an authentication protocol that has been around since the 1990s. It uses a password-based system and it is vulnerable to hacks. It is not secure against brute force attacks.

 

Kerberos is an authentication protocol that was created in the 1980s and it uses a ticket-based system. Kerberos is more secure than NTLM as it does not use passwords.

Kerberos Authentication

In Kerberos Authentication for Active Directory, there are multiple servers involved and the security is enhanced compared to NTLM. There is a Key Distribution Centre that manages the password for all accounts which hosts a database and two servers namely the Authentication server and the Ticket granting server.

 

The Authentication server is used to authenticate the user and provide a ticket (Ticket-granting ticket or TGT) which is verified by Ticket Granting Server and then grants the access to the server. Let’s see what exactly happens in a scenario when an internal client wants to access a server (let’s say web) in a network.

 

  1. An authentication request is sent to the Authentication server which contains the username, system time, and service information which is encrypted with user password hash.
  2. The Authentication server accesses the database that contains the user password hash, decrypts the request and then grants a TGT (Ticket-granting Ticket) to the user which is encrypted with the Key Distribution Centre’s (KDC) password hash and the session key required to access the web server which is encrypted with user password hash.
  3. Now, the client will send session key and TGT to the Ticket Granting Server (TGS) to acquire the service ticket to access the server.
  4. The TGS will check the TGT and decrypt it with KDC Password hash to verify the authenticity of the ticket. If valid, it provides the service ticket to access the server. This service ticket, contains the user password hash encrypted with the web server’s password hash. Thus, this can only be decrypted by the server.
  5. Now, the user holds a session key and a service ticket. This is sent to the web server.
  6. This service ticket is decrypted by the web server with its password hash to find out the user password hash. Then, the user password hash is used to decrypt the session key and then the data communication starts.
Kerberos Authentication
Kerberos Authentication

Understanding the Benefits: NTLM vs Kerberos Authentication

NTLM authentication is a protocol that is used to authenticate the user to the server. It is an extension of the challenge-response authentication protocol and uses a challenge-response mechanism.

 

Kerberos authentication is a computer network authentication protocol which provides strong security, prevents man-in-the-middle attacks, and uses no passwords.

 

NTLM authentication can be used on networks that are disconnected from other networks while Kerberos cannot.

 

NTLM allows for more complicated password policies than Kerberos does because it has a larger character set and can use Unicode characters.

Conclusion: Which One Should You Choose?

NTLM is an old and outdated protocol that was created in the 1990s. It has a number of security flaws, so many companies are moving to Kerberos.

 

As a result, NTLM is not really worth considering anymore.

Tags :
interview q&a, kerberos, Networking, ntlm
Share This :

2 comments

Leave a comment

Your email address will not be published. Required fields are marked *

Other Posts

Author

Have Any Question?

If you have any queries, please don’t hesitate to get in touch with us.