|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/kerberos-authentication-protocol-in-windows-domains/
课程评论:没有评论
**课程名称:** Windows域中的Kerberos认证 **课程概述:** 本课程提供一套精炼、标准化且经过验证的Kerberos认证信息,这些信息在公开渠道中难以找到。课程形式为演示,不包含互动实验或练习。内容高度浓缩,吸收消化需要远超3小时的学习时间,对学习者的积极性和学习能力有较高要求。每节课后均有复习及带解释的多项选择题。建议下载课程字幕代替记笔记,并参考文中引用的资料深入研究感兴趣的主题。 **课程内容:** * **Kerberos基础:** 介绍Microsoft实现的Kerberos认证协议及其优势、术语、概念和相关的服务基础设施。 * **Kerberos工作原理:** 通过详细的、分步的工单系统和各种配置下的通信消息的考察,利用流程图和网络流量分析器深入理解 Kerberos 的工作机制。掌握 Kerberos 的工作原理有助于解决复杂问题并减轻压力。 * **实际应用与配置:** 演示包括多跳设置和中间层服务集成在内的常见 Microsoft 应用程序(如 IIS、SQL、Exchange 和文件服务器)的 Kerberos 配置。 * **高级主题:** 探讨模拟(impersonation)、评审委派(delegation)选项,以及某些选项存在安全隐患的原因。 * **Kerberos化非Windows服务:** 学习如何为非 Windows 服务启用 Kerberos,从而享受 Kerberos 安全性和单点登录(SSO)的便利。 * **故障排除:** 深入研究 Kerberos 故障排除,提供一个避免常见误配置的检查清单,并展示具体的故障排除案例。 * **安全与攻击:** 考察 Kerberos 存在的漏洞和常见攻击方式,如 Kerberoasting、Golden Ticket 和 Silver Ticket 攻击,并讨论如何预防和检测这些攻击。 * **监控与告警:** 学习相关的监控和告警选项,以及如何利用这些功能检测恶意活动。
The course provides refined, standardized and verified information that cannot be found in any other single source publicly available. It does not contain engaging labs or tasks, but only demonstrations. The content is heavily condensed and it will take significantly more than 3 hours to absorb it. You will need a high level of motivation to be able to complete the course and digest the information so that it can be applied practically. At the end of each section, there is a review with multiple-choice questions and explanations. Download and use the course transcript instead of taking notes and follow the references for digging deeper in topics of interest.The course will introduce you to Microsoft implementation of Kerberos authentication protocol and its benefits, terminology, concepts, and service infrastructure. It will then explain how Kerberos works through detail and step-by-step examination of the ticketing system and communication messages in various configurations using flow diagrams and network traffic analyzer to get better understanding of the processes. Understanding how Kerberos works will help you with troubleshooting complex problems and reduce stress.We will walk through the configuration of the most common Microsoft applications such as IIS, SQL, Exchange, and file servers, including multi-hop setups and mid-tier service integration, discuss impersonation, review delegation options, and see why some of these options are not so secure. We will also learn how to Kerberize non-Windows services so they can benefit from Kerberos security and convenience of SSO. Then we will dive into troubleshooting issues, go through a checklist so we don't miss most common misconfigurations and we will look into specific troubleshooting examples. We will also examine Kerberos vulnerabilities and the most common attacks, such as Kerberoasting and Golden and Silver Tickets and talk about how to prevent and detect compromise. Finally, we will look into relevant monitoring and alerting options and learn how to use these for detecting malicious activity.