Kerberos is an authentication protocol that
enables a secure exchange of information between parties using unique
keys (called tickets) to identify the parties. With Kerberos, you
can authenticate users who access applications through the Authentication
Portal. With Kerberos SSO enabled, the user needs to log in only
for initial access to your network (such as logging in to Microsoft
Windows). After this initial login, the user can access any browser-based
service in the network without having to log in again until the
SSO session expires. To use Kerberos, you first need a a Kerberos
account for Prisma Access that will authenticate users. An account
is required to create a Kerberos keytab, which is a file that contains
the principal name and hashed password of the firewall or Panorama.
The SSO process requires the keytab. Kerberos SSO is available
only for services and applications that are internal to your Kerberos
environment. To enable SSO for external services and applications,
use SAML. |