Posts

Showing posts with the label Authentication

Federation Explained: SAML, OAuth and OIDC for the Security+ Exam

Federation is the arrangement that lets you sign in to a third-party application using an account you already hold somewhere else — logging into a vendor's portal with your work credentials, or into a service with your Google account. The application never sees your password. Federation means one organization trusts another organization's assertion about who you are, without ever holding your credentials. That last clause is the security argument. The application you are signing into gets a signed statement saying "this is Ken, and he authenticated successfully." It does not get a password to store, leak, or have stolen. The Three Roles Every federated login involves the same three parties, and exams expect the vocabulary. The principal — the user or entity trying to gain access. The identity provider (IdP) — the system that holds the credentials, performs the authentication, and issues the assertion. Entra ID, Okta, Google, Ping, ADFS. The service pr...

TOTP vs HOTP Explained: One-Time Passwords for the Security+ Exam

TOTP and HOTP are the two algorithms behind almost every authenticator app and hardware token you will encounter. They generate one-time passwords — the six-digit codes you type after your password — and the difference between them comes down to a single design decision. HOTP codes change when you use them. TOTP codes change when the clock does. Both are open standards, both use HMAC with a shared secret, and both produce the same kind of short numeric code. The distinction is what goes into the hash alongside the secret: a counter, or the time. HOTP — HMAC-Based One-Time Password Defined in RFC 4226. The server and the token share a secret key and a counter. To generate a code, both sides compute an HMAC-SHA-1 of the secret and the current counter value, then truncate the result to six or eight digits. The counter increments only when a code is generated or used . A code stays valid until it is consumed, which may be minutes or days later. That creates the characteristic...

Kerberos Explained: Tickets, the KDC and Kerberoasting for Security+

Kerberos is the authentication protocol at the heart of Active Directory, and it is the reason you type your password once at login and then reach file shares, printers, and applications all day without typing it again. It is named after the three-headed dog of Greek myth, which is a fair description of its three-party design. Kerberos proves who you are without ever sending your password across the network — not even encrypted. That is the central idea, and it is what separates Kerberos from the protocols it replaced. Older schemes transmitted passwords or password hashes that could be captured and replayed. Kerberos instead uses your password locally, as a key, to decrypt something only you should be able to decrypt. The Three Parties The client — the user or service requesting access. The Key Distribution Center (KDC) — the trusted third party, which in Active Directory is every domain controller. It has two functions: The Authentication Service (AS) , which verifies...