Subroutine Logo
Subroutine
← Back to Articles Security Intermediate 6 min read

Enterprise Auth Deep-Dive: NTLM vs Kerberos/SPNEGO vs mTLS

An interactive security exploration of Active Directory Kerberos ticket handshakes, NTLM challenge-response, and Mutual TLS (mTLS) PKI certificate authentication.

Published: 2026-07-28
#Security#Kerberos#NTLM#mTLS#Active Directory#PKI

Securing enterprise networks and modern microservice architectures requires choosing between legacy domain authentication (NTLM), Ticket-Granting Active Directory protocols (Kerberos / SPNEGO), and cryptographic zero-trust PKI architectures (Mutual TLS / mTLS).


1. Summary & Key Takeaways

  • NTLM (NT LAN Manager): Legacy challenge-response protocol. Susceptible to NTLM Relay attacks and Pass-the-Hash vulnerabilities because it verifies password hashes directly rather than issuing tickets.
  • Kerberos & SPNEGO: Uses a trusted third party - the Key Distribution Center (KDC) - to issue encrypted Ticket Granting Tickets (TGT) and Service Tickets (ST). Eliminates sending password hashes across the wire.
  • SPNEGO (Simple and Protected GSSAPI Negotiation Mechanism): A wrapper protocol that allows client and server to negotiate whether to use Kerberos or fall back to NTLM over HTTP headers (Authorization: Negotiate).
  • Mutual TLS (mTLS): Zero-trust network protocol authentication. Both client and server present X.509 Digital Certificates signed by a trusted Enterprise Certificate Authority (CA) during the TLS handshake, authenticating both endpoints cryptographically before any application data is sent.

2. Interactive Protocol Handshake Simulator

Step through the handshake sequence below to compare Kerberos/SPNEGO, NTLM Challenge-Response, and Mutual TLS (mTLS)!

Protocol Handshake Experiment

Select Kerberos or Mutual TLS (mTLS) and click “Next Step” to trace how tickets or PKI certificates authenticate clients and servers without transmitting passwords over the wire!

Enterprise Authentication Protocol Simulator

Step through Kerberos/SPNEGO, NTLM challenge-response, and Mutual TLS (mTLS) certificate handshakes

Step 1
Step 2
Step 3
Step 4
Step 5
1. Authentication Service Request (AS-REQ)Payload / Token

Client requests Ticket Granting Ticket (TGT) from KDC Key Distribution Center.

AS-REQ (Client ID + Timestamp)

3. Protocol Flow Comparison

graph TD
    subgraph Kerberos["Kerberos Ticket Flow"]
    C["Client"] -->|"1. AS-REQ"| KDC["KDC Key Center"]
    KDC -->|"2. TGT Ticket"| C
    C -->|"3. TGS-REQ + TGT"| KDC
    KDC -->|"4. Service Ticket ST"| C
    C -->|"5. AP-REQ + ST"| S["App Server"]
    end

    subgraph mTLS["Mutual TLS (mTLS) Flow"]
    C2["Client"] -->|"1. Client Hello + Client Cert"| S2["App Server"]
    S2 -->|"2. Server Hello + Verify Cert"| C2
    C2 -->|"3. Cert Signature Proof"| S2
    S2 -->|"4. mTLS Tunnel Established"| C2
    end

4. Authentication Method Matrix

ProtocolArchitectureVerification CredentialPassword Transmitted?Primary Use Case
NTLMChallenge-ResponseHash Response (TYPE 3)Hash Response SentLegacy Windows Domains
Kerberos / SPNEGOKDC Ticket BasedTGT & Service TicketsNeverActive Directory Domains
Mutual TLS (mTLS)PKI Certificate BasedX.509 Client Cert & RSA SignNeverZero-Trust Microservices