Lesson 04 - Group 3: Identity Management, SSO, and Federation

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/32

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:09 PM on 7/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

33 Terms

1
New cards
Authentication provider
A system that validates credentials or password hashes for local, network, or remote sign-in.
2
New cards
What Windows network authentication methods are listed?
Kerberos and NTLM.
3
New cards
What Linux files are associated with authentication?
/etc/passwd and /etc/shadow.
4
New cards
PAM
Pluggable Authentication Modules used by Linux authentication systems.
5
New cards
Directory service
A database of users, computers, groups, roles, services, and their authorizations.
6
New cards
LDAP
Lightweight Directory Access Protocol.
7
New cards
What does an LDAP distinguished name use?
Attribute=value pairs.
8
New cards
CN
Common Name in a distinguished name.
9
New cards
OU
Organizational Unit in a distinguished name.
10
New cards
O
Organization in a distinguished name.
11
New cards
C
Country in a distinguished name.
12
New cards
DC
Domain Component in a distinguished name.
13
New cards
SSO
Single sign-on; allows a user to authenticate once and access multiple authorized services.
14
New cards
Kerberos
A ticket-based authentication system that uses a Key Distribution Center.
15
New cards
KDC
Key Distribution Center.
16
New cards
What two services make up the Kerberos KDC workflow?
The Authentication Service and Ticket Granting Service.
17
New cards
TGT
Ticket Granting Ticket issued by the Authentication Service.
18
New cards
Service ticket
A ticket issued by the Ticket Granting Service for access to a particular application server.
19
New cards
What is the basic Kerberos ticket sequence?
The user receives a TGT, uses it to request a service ticket, and presents the service ticket to the application server.
20
New cards
Federation
Allows networks under separate administrative control to share user identities.
21
New cards
IdP
Identity Provider; authenticates the user and issues identity claims.
22
New cards
SP
Service Provider; relies on claims from an Identity Provider to grant access.
23
New cards
Claim
Information asserted by an Identity Provider about a user or account.
24
New cards
What relationship must exist between an IdP and SP?
A pre-established trust relationship using shared frameworks and protocols.
25
New cards
SAML
Security Assertion Markup Language; an open standard for communication between identity and service providers.
26
New cards
What format does SAML use?
XML.
27
New cards
How are SAML assertions protected?
They are signed using the XML signature specification.
28
New cards
What transport methods are listed for SAML?
HTTPS and SOAP.
29
New cards
OAuth
An authorization framework used by applications to request access to resources.
30
New cards
Does OAuth primarily provide authentication or authorization?
Authorization.
31
New cards
What technologies are associated with OAuth in Lesson 4?
RESTful APIs and JSON Web Tokens.
32
New cards
JWT
JavaScript Object Notation Web Token.
33
New cards
SAML versus OAuth
SAML communicates identity assertions between an IdP and SP, while OAuth communicates authorization for access to resource