Re: Kerberos UDP vs TCP



Kerberos is supposed to automatically switch to TCP if its message size
exceeds what UDP can handle. Kerberos messages get large when PAC data is
included in tickets (which seems to be most of the time now). There is so
little difference in overhead using TCP, that you don't notice it.

Kerberos is one of the few protocols that still uses UDP - most everything
else uses TCP. Because of this, using Kerberos over TCP should always work
correctly.

Paul Nelson
Thursby Software Systems, Inc.

in article AB16D9B0-A2DA-48C0-8015-ADF6022D6FD2@xxxxxxxxxxxxx, paolo
valsecchi at paolovalsecchi@xxxxxxxxxxxxxxxxxxxxxxxxx wrote on 11/14/06 3:18
AM:

Hi everybody
I'm facing some problems with Kerberos authentication using UDP protocol.
As suggested by Microsoft using TCP protocol the problem has been solved
instead.

Questions:
Why Microsoft uses UDP by default if there are authentication problems?
What would be the global impact on the network (WAN) using Kerberos
authentication through TCP? Would it be a suitable solution?

Any help really appreciated.


.



Relevant Pages

  • Re: TCP Resets
    ... I posted this in the AD forum yesterday, but got no responses, so I'm ... What we are seeing is a large number of TCP resets coming ... BTW...Looks like is it's doing Kerberos over TCP ... Instead of the website you're using, I suggest to use OEx (Outlook Express ...
    (microsoft.public.windows.server.networking)
  • Re: TCP Resets
    ... What we are seeing is a large number of TCP resets coming ... from our AD Domain Controllers, ... Network Error:TCP Reset ... t say if this is normal or not, but it doesn't appear correct, since you mentioned Kerberos using TCP. ...
    (microsoft.public.windows.server.networking)
  • Re: Antivirus in FC3?
    ... >> it adds some fields for carrying group information, and uses TCP ... modifying a cryptoanalyzed protocol like Kerberos V in such a ... >> way doesn't mean automatically that Windows's Kerberos V modified ...
    (Fedora)
  • Kerio 2.1.5 and LSA Shell, Windows Logon Application rules
    ... Protocol: TCP ... Local: Any port ... Remote: Any address:88 ... What is LDAP and Kerberos? ...
    (comp.security.firewalls)
  • NFS problem with recent 2.6 kernels (also serial console weirdness)
    ... 100000 2 tcp 111 portmapper ... 100000 2 udp 111 portmapper ... mounted filesystem with ordered data mode. ... Mounted root (ext3 filesystem) readonly. ...
    (Linux-Kernel)