Home > Data Storage Tips > SAN/NAS Update > Kerberos and its place in NAS authentication
Storage UK Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SAN/NAS UPDATE

Kerberos and its place in NAS authentication


Christopher Poelker
08.02.2006
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


NAS security tip: NAS environments can benefit from the use of Kerberos.

Kerberos security has been around since the 1980s, but many people are still unfamiliar with how Kerberos works, where it's used and how it may help improve security for users of network attached storage (NAS) resources.

((Content component not found.)) Kerberos, derived from the name of the three-headed dog that guarded the gates to Hades in Greek mythology, was developed as a security project at MIT during the 1980s to help improve network security. Early password authentication and access control lists helped provide security for data within a machine, but passwords sent over a network as clear text for access to remote resources was not secure since it could be "sniffed" or "hacked" by malicious users.

Kerberos authentication:

  • Provides "single sign on" for network resources.
  • Provides strong authentication services for client/server applications by using key based authentication services rather than passing clear or encrypted passwords over the network.
  • Provides a centralized security mechanism for network access.

Kerberos is used only for network-level security, and does NOT provide a mechanism to protect the actual stored files. Operating system level permissions are still required to control access to files. When a user logs onto a network that uses Kerberos security, that user is understood to be a trusted user, and uses that login credential to access all resources the user was granted. Kerberos is now the default network security mechanism used for Windows 2000 and 2003 active directory running in native mode. Traditional NTLM security (which is less secure) is used for "mixed-mode" security to support legacy Windows NT servers.

When using Kerberos security, passwords are never transmitted over the network. Instead, users contact the Active Directory, a Kerberos server or the Kerberos Key Distribution Center (KDC) service, which stores and retrieves all information about security. Clients requesting access to services on another computer, such as a NAS share, contact the KDC directly to obtain their session credentials -- or "ticket" -- to gain access permissions to the network resource.

Windows CIFS-based NAS Resources

If you are using Windows XP to access a NAS share on a Windows server that is using native mode active directory security, then you are probably using Kerberos without even knowing about it. If your network uses "mixed mode" security to provide backward compatibility for Windows NT networks, then you may be using the older and less secure CHAP protocol. If your NAS storage provider allows native active directory integration for security, then they should provide Kerberos security by default.

Unix-based NFS NAS resources

Unix NFS-based NAS resources are a different story. Unless your NAS provider uses NFSV4, it may not be integrated with Kerberos security. Although NFS versions 2 and 3 support Kerberos (version 2 supports Kerberos version 4, while NFSV3 and NFSV4 support Kerberos version 5), they must be integrated with an existing Kerberos server. Also, you need to make sure that your Unix clients (Linux, Solaris, HP-UX, AIX, Tru64, etc.) also support integrated Kerberos security. Contact your NAS provider to find out which Unix clients they support using Kerberos security.

Integrating Kerberos security for access to NAS resources provides an added layer of protection that assures users accessing the network are trusted. Since Kerberos uses keys rather than passwords, network resources are more secure. Kerberos may already be in place for Windows CIFS shares using native mode active directory security. NFS NAS shares need to be integrated with a Unix-based Kerberos server. For more information, visit this MIT Web site about Kerberos.

Do you know...

How to tame NAS sprawl?

The top NAS products on the market?

About the author: Christopher Poelker is the co-author of SAN for Dummies.


Rate this Tip
To rate tips, you must be a member of SearchStorage.co.UK.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
SAN/NAS Update
NAS systems evolve but remain simple to operate
How to size a SAN
Dispelling myths about clustering NAS and file servers
Clustered NAS gaining in popularity
Network attached storage (NAS) basics
RAID 6 vs. RAID 10
Don't let NAS consolidation impair performance
Using global spare drives to increase SAN reliability
How to create a SAN performance baseline
Tutorial: Creating a tiered SAN architecture

NAS management
Unified storage simplifies things for admins managing NAS and SAN
Unified storage categories
Attune file virtualization software reports on Windows NAS performance
Ocarina upgrades its ECO System compression appliance
Ibrix rolls out tiered file migration
Storage pros look to pNFS for VMware performance boost
NAS systems evolve but remain simple to operate
Dispelling myths about clustering NAS and file servers
Animal charity opts for clustered NAS over iSCSI SAN
NetApp automates VMware snapshots, storage provisioning

Secure data storage
CommVault, McAfee partner to integrate storage and security management solution
Storage news in brief
Notes from SNW: Encryption shifts to disk drives
8 steps to better data security
Policy and technology: the belt and braces of data protection
Iron Mountain digitizes documents to bolster security
Disclosure becomes a fact of life in leaky Britain
nCipher grabs NeoScale for $1.9M
How to mitigate the performance penalties of data encryption software
Users: Storage security becoming a priority

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts