 |
Kerberos: The Definitive Guide by Jason Garman
Book Summary InformationAuthor: Jason Garman Edition: Paperback Audio: English (Original Language); English (Unknown); English (Published) Format: Illustrated Published: 2003-12-15 ISBN: 0596004036 Number of pages: 270 Publisher: O'Reilly Media, Inc.
Book Reviews of Kerberos: The Definitive GuideBook Review: Will Get You Up and Running (1stEd) Summary: 5 StarsFirst I would like to justify my 5 star rating. This book helped me out of a nasty multi-homed host and DNS problem when no other source could. Without this book I would have been troubleshooting this issue for days. I feel the book has paid for itself.
However, I wouldn't consider this "The Definitive Guide." It lacks documentation on the krb5.conf configuration file. I found myself referencing the krb5.conf(5) man page for additional info. Also, the documentation that comes with Heimdal is a very good good source for configuration settings.
Another deficiency is the GSSAPI coverage. I did have some trouble setting up my GSSAPI aware SSH with Kerberos. I found myself digging through the ssh man pages and doing some trial and error. Chapter 7 discusses Kerberos enabled applications. SSH is covered there, but I felt the GSSAPI aspect was lacking. Although the author mentions that GSSAPI is not specific to any authentication method and is somewhat out of place in a Kerberos book, I feel this is where the author could have went the extra mile and claimed the right to the title "The Definitive Guide." There are many Kerberized applications today not mentioned in Chapter 7. It would be nice to see a second edition that covers them.
What this book has that you will not find in any other single source is comprehensive coverage of the history, protocols, and implementation of Kerberos complete with diagrams. From a security standpoint, this will really help you understand what is going on in your network. For example, when setting up my firewall rules and NIDS, I really had a grasp on what traffic was going where and what needed to be blocked/detected.
Chapter 6, Security, is very comprehensive and outlines various root compromises, dictionary and brute-force, replay, and man-in-the-middle attacks. It also details the importance of pre-authentication in Kerberos V as well as best practices to protect your key distribution center (KDC).
My Kerberos network is a 10 host homogeneous OpenBSD network running the Heimdal Kerberos V version 0.7.2. Although this book covers the older Heimdal 0.6, it was still very relevant. It also covers the MIT 1.3 implementation (MIT is currently at version 1.6.3). Although this book was published in 2003, it is still worth its price brand new in 2008.
Summary of Kerberos: The Definitive GuideKerberos, the single sign-on authentication system originally developed at MIT, deserves its name. It's a faithful watchdog that keeps intruders out of your networks. But it has been equally fierce to system administrators, for whom the complexity of Kerberos is legendary. Single sign-on is the holy grail of network administration, and Kerberos is the only game in town. Microsoft, by integrating Kerberos into Active Directory in Windows 2000 and 2003, has extended the reach of Kerberos to all networks large or small. Kerberos makes your network more secure and more convenient for users by providing a single authentication system that works across the entire network. One username; one password; one login is all you need. Fortunately, help for administrators is on the way. "Kerberos: The Definitive Guide" shows you how to implement Kerberos for secure authentication. In addition to covering the basic principles behind cryptographic authentication, it covers everything from basic installation to advanced topics like cross-realm authentication, defending against attacks on Kerberos, and troubleshooting. In addition to covering Microsoft's Active Directory implementation, "Kerberos: The Definitive Guide" covers both major implementations of Kerberos for Unix and Linux: MIT and Heimdal. It shows you how to set up Mac OS X as a Kerberos client. The book also covers both versions of the Kerberos protocol that are still in use: Kerberos 4 (now obsolete) and Kerberos 5, paying special attention to the integration between the different protocols, and between Unix and Windows implementations. If you've been avoiding Kerberos because it's confusing and poorly documented, it's time toget on board! This book shows you how to put Kerberos authentication to work on your Windows and Unix systems.
|
 |
Kerberos: The Definitive Guideby Jason Garman O'Reilly Media, Inc.; Published: 2003-12-15; Paperback; BookBest price: $9.77Price in other shops: $34.95
SSH, The Secure Shell: The Definitive Guideby Daniel J. Barrett, Richard Silverman O'Reilly; Published: 2001-02-15; Paperback; BookBest price: $8.97Price in other shops: $39.95
Sun Certified Network Administrator for Solaris 8 Operating Environment Study Guide (Sun Microsystems Press)by Rick Bushnell Prentice Hall PTR; Published: 2002-05-25; Paperback; BookBest price: $22.96Price in other shops: $39.99
TCP/ IP Network Administration (3rd Edition; O'Reilly Networking)by Craig Hunt O'Reilly Media, Inc.; Published: 2002-04; Paperback; BookBest price: $22.45Price in other shops: $44.95
Practical Unix & Internet Security, 3rd Editionby Simson Garfinkel, Gene Spafford, Alan Schwartz O'Reilly Media, Inc.; Published: 2003-02-21; Paperback; BookBest price: $10.86Price in other shops: $54.95
Solaris(TM) Internals (Solaris Series)by Jim Mauro, Richard McDougall, Sun Microsystems Press Prentice Hall PTR; Published: 2000-10-15; Paperback; BookBest price: $3.21Price in other shops: $69.99
DNS & BIND Cookbookby Cricket Liu O'Reilly Media, Inc.; Published: 2002-10; Paperback; BookBest price: $3.62Price in other shops: $34.95
DNS and BIND, Fourth Editionby Paul Albitz, Cricket Liu O'Reilly Media, Inc.; Published: 2001-04-16; Paperback; BookBest price: $6.19Price in other shops: $44.95
sendmail Performance Tuningby Nick Christenson Pearson Education; Published: 2002-09-12; Paperback; BookBest price: $24.00Price in other shops: $34.99
sendmail, 3rd Editionby Bryan Costales, Eric Allman O'Reilly Media, Inc.; Published: 2002-12; Paperback; BookBest price: $16.68Price in other shops: $59.95
|
Network Warriorby Gary A. Donahue O'Reilly Media, Inc.; Published: 2007-06-01; Paperback; BookBest price: $25.68Price in other shops: $44.99
Backup & Recoveryby W. Curtis Preston O'Reilly Media, Inc.; Published: 2007-01-03; Paperback; BookBest price: $28.46Price in other shops: $49.99
Radiusby Jonathan Hassell O'Reilly Media, Inc.; Published: 2002-10-08; Paperback; BookBest price: $25.11Price in other shops: $34.95
Active Directory Cookbook, 2nd Editionby Robbie Allen, Laura Hunter O'Reilly Media, Inc.; Published: 2006-06-09; Paperback; BookBest price: $28.94Price in other shops: $49.99
Using Samba (O'Reilly System Administration)by Robert Eckstein, David Collier-Brown, Peter Kelly Published: 1999-10-31; Paperback; BookBest price: $15.80Price in other shops: $34.95
Dns and Bindby Cricket Liu, Paul Albitz, Mike Loukides O'Reilly; Published: 1998-09; Paperback; BookBest price: $16.71Price in other shops: $32.95
Network Security with OpenSSLby John Viega, Matt Messier, Pravir Chandra O'Reilly Media, Inc.; Published: 2002-06-15; Paperback; BookBest price: $21.79Price in other shops: $39.95
SSH, The Secure Shell: The Definitive Guideby Daniel J. Barrett, Richard E. Silverman, Robert G. Byrnes O'Reilly Media, Inc.; Published: 2005-05-10; Paperback; BookBest price: $22.84Price in other shops: $39.95
Active Directory, 3rd Editionby Joe Richards, Robbie Allen, Alistair Lowe-Norris O'Reilly Media, Inc.; Published: 2006-01-19; Paperback; BookBest price: $29.50Price in other shops: $49.99
LDAP System Administrationby Gerald Carter O'Reilly Media, Inc.; Published: 2003-03-20; Paperback; BookBest price: $16.55Price in other shops: $39.95
|