Is Kerberos prone to Brute Force attack?

Kerberos is vulnerable to Password guessing as it cannot detect a dictionary attack. So when we are talking about Kerberos, let me tell you some more weaknesses too:

  • It Provides Authentication, confidentiality and integrity, but not availability or non-repudiation (as it uses Symmetric Keys).
  • The KDC is a single Point of failure. If compromised, the integrity of the whole network is compromised.
  • Secret Keys are stored on User's Workstations. Even the session keys are stored on user?s workstations in cache or key tables.

