skip to content

Directory & AAA

LDAP directory search and binds, Kerberos ticket exchange, RADIUS Access-Request flows and TACACS+ per-command authorization. Interviewers probe how enterprise and network logins are checked.

on this pageshow

explore

questions

140 · 4 sections

In LDAP, what does the Bind operation do to a session, and what state is that session in before one?

level: juniorimportance: must knowfreq 55%
basics
~20 s

The LDAP Bind operation sets the authentication state of an LDAP session. Before any Bind, and after any Bind that fails, the session is anonymous: it can already send searches, but every request is evaluated as an unauthenticated caller.

open as a page

In LDAPv3, how does a Control attached to a request differ from an extended operation?

level: juniorimportance: must knowfreq 46%
basics
~20 s

An LDAP Control rides along on a request the protocol already defines and changes how the server carries it out. An extended operation is a whole new request, named by its own OID, that the base operation set never had.

open as a page

In LDAP, how is a directory entry's Distinguished Name built from its own RDN and its ancestors'?

level: juniorimportance: must knowfreq 58%
basics
~20 s

A Distinguished Name chains the entry's own Relative Distinguished Name onto every ancestor's, up to the naming context the server holds. In the RFC 4514 string form the leftmost component is the entry itself and the rightmost sits nearest the root.

open as a page

When a directory server answers an LDAP write request, what does the LDAPResult in that reply tell the client?

level: juniorimportance: must knowfreq 48%
basics
~20 s

LDAPResult is the shared reply body for Add, Modify, ModifyDN, Delete and Compare. It carries a numeric resultCode such as success(0), a matchedDN showing how far the server resolved the name, and a human-readable diagnosticMessage.

open as a page

In LDAP, what does a directory entry's objectClass attribute declare, and why must every entry carry one?

level: juniorimportance: must knowfreq 52%
basics
~20 s

A directory entry's objectClass attribute names the classes the entry belongs to, and those classes' MUST and MAY lists decide which attributes it may hold. The abstract class top requires the attribute, so every entry carries it.

open as a page

In Kerberos, what does one sign-in at the KDC give a user, and why does a file archive server never see the password?

level: juniorimportance: must knowfreq 55%
basics
~20 s

One sign-in returns a ticket-granting ticket plus a session key. The user spends that ticket at the ticket-granting service for a short-lived service ticket, and the archive server validates that ticket with its own long-term key — the password itself never reaches it.

open as a page

In HTTP Negotiate authentication, what is inside the base64 value of the Authorization header a client sends?

level: juniorimportance: must knowfreq 42%
basics
~10 s

A GSS-API context-establishment token, normally a SPNEGO NegTokenInit wrapping a Kerberos AP-REQ built from a service ticket. It is one leg of a handshake for one service, not the user's password.

open as a page

In a Kerberos AS-REP, which key seals the ticket-granting ticket and which key seals the enc-part beside it?

level: middleimportance: must knowfreq 58%
basics
~20 s

The ticket-granting ticket is sealed under the krbtgt principal's long-term key, so the requesting client cannot open it. The AS-REP's enc-part beside it is sealed under the client's own long-term key and carries the session key, the ticket flags and the expiry times.

open as a page

What does a KDC's KDC_ERR_PREAUTH_REQUIRED reply to a Kerberos AS-REQ tell the client to do?

level: middleimportance: must knowfreq 50%
basics
~20 s

KDC_ERR_PREAUTH_REQUIRED (25) means the KDC will not issue a ticket until the client proves it holds its long-term key. The error's e-data carries METHOD-DATA listing the pre-authentication types accepted, and the client resends the AS-REQ with PA-ENC-TIMESTAMP.

open as a page

In Kerberos, which exchange does Pass-the-Ticket use, and what does the service check before accepting the stolen service ticket?

level: middleimportance: must knowfreq 58%
basics
~20 s

Pass-the-Ticket runs the AP exchange only: an AP-REQ carrying the stolen service ticket plus a fresh Authenticator sealed under that ticket's session key. The service checks decryption, names and timestamp, never who copied the ticket.

open as a page

In RADIUS, which device acts as the client and sends the Access-Request, and where does the end user's laptop sit?

level: juniorimportance: must knowfreq 58%
basics
~20 s

The network access server - the switch, wireless access point or remote-access concentrator the user connects through - is the RADIUS client and sends the Access-Request. The user's laptop sends no RADIUS packet at all; it is the subject of the exchange.

open as a page

Across one subscriber session, which Acct-Status-Type (40) values does a network access server send, and when?

level: juniorimportance: must knowfreq 46%
basics
~20 s

Acct-Status-Type (40) marks each RADIUS accounting record: Start (1) when the session begins, Interim-Update (3) on a timer while it runs, and Stop (2) when it ends. Each record goes to UDP port 1813 as an Accounting-Request (Code 4).

open as a page

In RADIUS, what does a pass-through authenticator do with an EAP conversation it cannot interpret?

level: juniorimportance: must knowfreq 52%
basics
~20 s

A pass-through authenticator copies every EAP packet between the peer and the RADIUS server inside EAP-Message (79) attributes without parsing the method, so the server terminates EAP-TLS or a tunnelled method and the access device only applies the verdict it gets back.

open as a page

In RADIUS, which three reply codes can answer an Access-Request, and what does each one mean?

level: juniorimportance: must knowfreq 62%
basics
~10 s

A RADIUS server answers an Access-Request with Access-Accept (Code 2), Access-Reject (Code 3) or Access-Challenge (Code 11). Accept and reject end the exchange; a challenge asks for more input and expects a further Access-Request.

open as a page

Why does a RADIUS Access-Accept carry the session's authorization attributes while accounting is a separate exchange?

level: middleimportance: must knowfreq 55%
basics
~20 s

RADIUS answers authentication and authorization in one round trip: the attributes inside an Access-Accept are the grant, so there is no second request. Accounting is a different exchange, with its own packet codes and normally its own port, and it can fail on its own.

open as a page

In TACACS+ device administration, which party sends an accounting REQUEST, and what is that exchange for?

level: juniorimportance: must knowfreq 45%
basics
~20 s

The network device sends it — in TACACS+ the client is the device, not the human at the keyboard. The accounting exchange is a REQUEST/REPLY pair asking the device-administration server to record what happened, after the fact.

open as a page

In TACACS+, what does one session cover, and what transport connection carries it?

level: juniorimportance: must knowfreq 48%
basics
~20 s

A TACACS+ session is one authentication sequence, one authorization exchange or one accounting exchange, named by session_id in the header. It travels over a TCP connection to port 49 that the network device opens to the device-administration server.

open as a page

TACACS+ uses TCP port 49 and RADIUS uses UDP ports 1812 and 1813 — what follows from that?

level: juniorimportance: must knowfreq 56%
basics
~20 s

TACACS+ over TCP port 49 gets ordered, acknowledged delivery and an explicit connection whose loss is visible, so it can hold a multi-exchange conversation open. RADIUS over UDP makes the network access server own retransmission and server-liveness guessing itself.

open as a page

In a TACACS+ accounting REQUEST, what do the START, STOP and WATCHDOG flags mean, and which combinations are legal?

level: middleimportance: must knowfreq 55%
basics
~20 s

START opens a task, STOP closes it, WATCHDOG says a long-running task is still alive. START and STOP are mutually exclusive, STOP must not be combined with WATCHDOG, and WATCHDOG with START means the update carries new or changed arguments.

open as a page

In a TACACS+ authentication exchange, which side decides that another prompt is needed, and how does the network device learn what to ask?

level: middleimportance: must knowfreq 52%
basics
~20 s

The device-administration server decides. Its REPLY carries a status — GETUSER, GETPASS or GETDATA — and a server_msg the network device displays as the prompt; the device answers with one CONTINUE and waits for the next REPLY.

open as a page