Kerberos
Focus
Focus
Strata Cloud Manager

Kerberos

Table of Contents


Kerberos

Learn to configure Kerberos authentication Profiles.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • NGFW, including those funded by Software NGFW Credits
Each of these licenses include access to Strata Cloud Manager:
→ The features and capabilities available to you in Strata Cloud Manager depend on which license(s) you are using.
Kerberos is a computer network authentication protocol that uses tickets to allow nodes that communicate over a non-secure network to provide their identity to one another in a secure manner.
The authentication profile specifies the server profile that the portal or gateways use when they authenticate users. Follow these steps to set up Kerberos authentication profile for Explicit Proxy mobile users to connect to Prisma Access, for administrators to connect to the firewall web interface, and for end users to log in to the Authentication Portal.
  1. Go to ManageConfigurationIdentity ServicesAuthenticationAuthentication Profiles and Add Profile.
  2. Select the Authentication Method: Kerberos.
  3. Enter the Profile Name to identify the server profile. The authentication profile specifies the server profile that the portal or gateways use when they authenticate users.
  4. Enter the Kerberos Realm (up to 127 characters) to specify the hostname portion of the user login name. For example, the user account name user@EXAMPLE.LOCAL has the realm EXAMPLE.LOCAL.
  5. Import a Kerberos Keytab file which contains the Kerberos account information. When prompted, browse for the keytab file, and then click Save. During authentication, the endpoint first attempts to establish SSO using the keytab.
  6. Choose the Kerberos Keytab.
  7. Click Save.