Kerberos SSO End-to-End: Fundamentals, Flows, and Advanced Troubleshooting
-
Register
- Member - Free!
This session provides an end-to-end, practitioner-focused deep dive into Kerberos based Single Sign-On on IBM i, designed to be approachable for those new to the technology while still delivering real value to experienced engineers. We start by clearly explaining the core Kerberos concepts—tickets, principals, SPNs, and authentication flows—then progressively peel back the layers to show what actually happens during successful and failed logins. We will cover how both Network Authentication Services (NAS) and Enterprise Identity Mapping (EIM) work together within the IBM i. From there, we move beyond theory into real-world behavior, covering both single-hop and multi-hop (delegation) scenarios and why they so often break in enterprise environments. We will conclude the session by diving into advanced diagnostics and troubleshooting techniques, including common misconfigurations, delegation pitfalls, clock and DNS issues, and how to interpret logs and traces to pinpoint failures. Attendees will leave with a practical mental model of Kerberos, a clear understanding of how SSO works across hops, and concrete techniques they can immediately apply to debug complex authentication problems in production.
Robert Andrews
Team Lead
IBM
Robert Andrews is the Team Lead for the IBM i Security and Authentication Lab Services Power Systems Delivery Practice in Rochester, MN. He is an Executive Security Consultant and a certified Thought Leader in IBM for security. Besides security, Robert is an expert in Db2, journaling, and DDM/DRDA. In addition to his technical work at IBM, Robert has been strongly involved in Emergency Management and Communications for over a decade at all levels from local to federal. Robert has published seven books and holds degrees in mathematics, computer science, education, and management.