Securing enterprise networks and modern microservice architectures requires choosing between legacy domain authentication (NTLM), Ticket-Granting Active Directory protocols (Kerberos / SPNEGO), and cryptographic zero-trust PKI architectures (Mutual TLS / mTLS).
1. Summary & Key Takeaways
- NTLM (NT LAN Manager): Legacy challenge-response protocol. Susceptible to NTLM Relay attacks and Pass-the-Hash vulnerabilities because it verifies password hashes directly rather than issuing tickets.
- Kerberos & SPNEGO: Uses a trusted third party - the Key Distribution Center (KDC) - to issue encrypted Ticket Granting Tickets (TGT) and Service Tickets (ST). Eliminates sending password hashes across the wire.
- SPNEGO (Simple and Protected GSSAPI Negotiation Mechanism): A wrapper protocol that allows client and server to negotiate whether to use Kerberos or fall back to NTLM over HTTP headers (
Authorization: Negotiate). - Mutual TLS (mTLS): Zero-trust network protocol authentication. Both client and server present X.509 Digital Certificates signed by a trusted Enterprise Certificate Authority (CA) during the TLS handshake, authenticating both endpoints cryptographically before any application data is sent.
2. Interactive Protocol Handshake Simulator
Step through the handshake sequence below to compare Kerberos/SPNEGO, NTLM Challenge-Response, and Mutual TLS (mTLS)!
Select Kerberos or Mutual TLS (mTLS) and click “Next Step” to trace how tickets or PKI certificates authenticate clients and servers without transmitting passwords over the wire!
Enterprise Authentication Protocol Simulator
Step through Kerberos/SPNEGO, NTLM challenge-response, and Mutual TLS (mTLS) certificate handshakes
Client requests Ticket Granting Ticket (TGT) from KDC Key Distribution Center.
3. Protocol Flow Comparison
graph TD
subgraph Kerberos["Kerberos Ticket Flow"]
C["Client"] -->|"1. AS-REQ"| KDC["KDC Key Center"]
KDC -->|"2. TGT Ticket"| C
C -->|"3. TGS-REQ + TGT"| KDC
KDC -->|"4. Service Ticket ST"| C
C -->|"5. AP-REQ + ST"| S["App Server"]
end
subgraph mTLS["Mutual TLS (mTLS) Flow"]
C2["Client"] -->|"1. Client Hello + Client Cert"| S2["App Server"]
S2 -->|"2. Server Hello + Verify Cert"| C2
C2 -->|"3. Cert Signature Proof"| S2
S2 -->|"4. mTLS Tunnel Established"| C2
end
4. Authentication Method Matrix
| Protocol | Architecture | Verification Credential | Password Transmitted? | Primary Use Case |
|---|---|---|---|---|
| NTLM | Challenge-Response | Hash Response (TYPE 3) | Hash Response Sent | Legacy Windows Domains |
| Kerberos / SPNEGO | KDC Ticket Based | TGT & Service Tickets | Never | Active Directory Domains |
| Mutual TLS (mTLS) | PKI Certificate Based | X.509 Client Cert & RSA Sign | Never | Zero-Trust Microservices |