1
00:00:06,660 --> 00:00:10,800
- [Instructor] Servers part
four, authentication servers.

2
00:00:10,800 --> 00:00:15,150
An authentication server
acts as a central repository

3
00:00:15,150 --> 00:00:19,380
of user accounts and computer
accounts on the network.

4
00:00:19,380 --> 00:00:23,400
All users log on to this server.

5
00:00:23,400 --> 00:00:25,230
The information about the users

6
00:00:25,230 --> 00:00:27,933
can be shared with other servers as well.

7
00:00:28,830 --> 00:00:31,260
So here in our illustration
we have an example.

8
00:00:31,260 --> 00:00:33,240
We've added another server here,

9
00:00:33,240 --> 00:00:36,780
the authentication server to our LAN.

10
00:00:36,780 --> 00:00:39,240
And quite often in a lot of companies

11
00:00:39,240 --> 00:00:43,950
this will be a Windows
Server that has been promoted

12
00:00:43,950 --> 00:00:46,713
and has become a domain controller.

13
00:00:47,670 --> 00:00:52,200
And all the users at these
computers log onto that server.

14
00:00:52,200 --> 00:00:55,260
And that server takes care
of the authentication,

15
00:00:55,260 --> 00:00:59,850
verifying the username and
passwords of those users

16
00:00:59,850 --> 00:01:02,820
and making sure those
computers are allowed access

17
00:01:02,820 --> 00:01:04,530
to the domain as well.

18
00:01:04,530 --> 00:01:07,560
But the authentication server
could also be on the internet.

19
00:01:07,560 --> 00:01:11,400
If you have multiple offices
or if you have a smaller office

20
00:01:11,400 --> 00:01:15,690
and you don't wanna run an
authentication server locally,

21
00:01:15,690 --> 00:01:18,600
you could run that on the cloud

22
00:01:18,600 --> 00:01:21,690
with a provider, a cloud
provider, or possibly something

23
00:01:21,690 --> 00:01:24,843
that you've placed in another location.

24
00:01:25,710 --> 00:01:29,640
So it could be on the internet
or it could be in the LAN.

25
00:01:29,640 --> 00:01:34,050
Larger companies will
quite often have them

26
00:01:34,050 --> 00:01:36,600
on the Local Area Network.

27
00:01:36,600 --> 00:01:39,390
And what this does is it speeds up

28
00:01:39,390 --> 00:01:41,250
the authentication process.

29
00:01:41,250 --> 00:01:43,080
Without the internet involved,

30
00:01:43,080 --> 00:01:46,230
all of these computers
and users logging in

31
00:01:46,230 --> 00:01:48,780
will have a faster, more efficient process

32
00:01:48,780 --> 00:01:51,660
if the authentication server is on the LAN

33
00:01:51,660 --> 00:01:56,660
but that increases the
manpower needed to maintenance,

34
00:01:57,210 --> 00:02:00,900
to maintain and take care of that server.

35
00:02:00,900 --> 00:02:04,530
Generally, small companies,
small offices, home offices,

36
00:02:04,530 --> 00:02:06,990
will not have an authentication server

37
00:02:06,990 --> 00:02:08,850
'cause it's really not necessary

38
00:02:08,850 --> 00:02:11,670
but larger companies will require this

39
00:02:11,670 --> 00:02:14,670
in order to centralize the user accounts

40
00:02:14,670 --> 00:02:17,940
and keep everything nice and organized.

41
00:02:17,940 --> 00:02:21,240
And especially if you're
gonna have file servers

42
00:02:21,240 --> 00:02:23,370
that you wanna have hundreds of people

43
00:02:23,370 --> 00:02:26,610
connecting to at the same time,
that authentication server,

44
00:02:26,610 --> 00:02:30,240
that domain controller in Windows networks

45
00:02:30,240 --> 00:02:34,590
will allow for this, it'll
facilitate the quick and easy

46
00:02:34,590 --> 00:02:37,323
and efficient connections
that are necessary.

47
00:02:38,190 --> 00:02:40,590
Now, the authentication
server uses one or more

48
00:02:40,590 --> 00:02:42,600
authentication protocols.

49
00:02:42,600 --> 00:02:45,300
For example, LDAP,

50
00:02:45,300 --> 00:02:48,960
that's the Lightweight
Directory Access Protocol.

51
00:02:48,960 --> 00:02:51,570
This is a vendor-neutral standard

52
00:02:51,570 --> 00:02:56,070
used to access directory
information services.

53
00:02:56,070 --> 00:02:58,980
Various types of software use it,

54
00:02:58,980 --> 00:03:01,980
for example Windows Servers
that have been promoted

55
00:03:01,980 --> 00:03:04,530
to domain controllers.

56
00:03:04,530 --> 00:03:07,080
It's standardized by the IETF

57
00:03:07,080 --> 00:03:11,760
and published as a request
for comments RFC 4511.

58
00:03:13,620 --> 00:03:18,120
It's based on the X.500 standard.

59
00:03:18,120 --> 00:03:21,543
And it's sometimes called X.500 light.

60
00:03:23,490 --> 00:03:24,960
Another one is Kerberos.

61
00:03:24,960 --> 00:03:27,810
This is another type of
authentication protocol.

62
00:03:27,810 --> 00:03:32,810
If you have an insecure
network by default,

63
00:03:33,270 --> 00:03:38,270
but you want your computers
to prove their identity

64
00:03:38,370 --> 00:03:41,940
to an authentication
server in a secure manner,

65
00:03:41,940 --> 00:03:44,340
then Kerberos can be the solution.

66
00:03:44,340 --> 00:03:48,120
It uses tickets and symmetric encryption

67
00:03:48,120 --> 00:03:49,863
to authenticate computers.

68
00:03:51,180 --> 00:03:54,960
An example of an authentication
server that runs LDAP

69
00:03:54,960 --> 00:03:59,493
and possibly uses Kerberos
as well is Windows Server.

70
00:04:00,540 --> 00:04:01,920
Let's show an example of this

71
00:04:01,920 --> 00:04:04,833
and we'll go to our Server 2012 here.

72
00:04:05,700 --> 00:04:07,260
And we're in the Server Manager

73
00:04:07,260 --> 00:04:11,040
and originally this
was just a file server.

74
00:04:11,040 --> 00:04:12,900
That's all it was when
I first installed it

75
00:04:12,900 --> 00:04:15,360
and that's what you get by default.

76
00:04:15,360 --> 00:04:18,303
But I wanted to create a domain.

77
00:04:19,170 --> 00:04:21,240
And if you want to create a domain

78
00:04:21,240 --> 00:04:26,240
or connect to a preexisting domain,

79
00:04:26,520 --> 00:04:29,073
then you'd have to
install Active Directory.

80
00:04:29,940 --> 00:04:34,200
And that's the full name, Active
Directory Domain Services.

81
00:04:34,200 --> 00:04:38,260
So I did that, I did a
promotion to promote that server

82
00:04:39,390 --> 00:04:41,793
to a domain controller.

83
00:04:43,140 --> 00:04:46,080
And to do that, we also needed DNS

84
00:04:46,080 --> 00:04:49,200
because Active Directory

85
00:04:49,200 --> 00:04:51,960
needs to actually look to a DNS server.

86
00:04:51,960 --> 00:04:53,850
So this is running both of those.

87
00:04:53,850 --> 00:04:56,760
But the DNS server could be a separate box

88
00:04:56,760 --> 00:04:58,350
on the Local Area Network,

89
00:04:58,350 --> 00:05:00,840
could be a separate box
out on the internet.

90
00:05:00,840 --> 00:05:02,550
In many large companies,

91
00:05:02,550 --> 00:05:04,740
they will be in the same server room.

92
00:05:04,740 --> 00:05:06,420
They might be separate boxes

93
00:05:06,420 --> 00:05:09,840
but they'll be in the same
server room or data center.

94
00:05:09,840 --> 00:05:14,670
So we install that Active
Directory and that installs LDAP,

95
00:05:14,670 --> 00:05:17,130
the Lightweight Directory Access Protocol,

96
00:05:17,130 --> 00:05:20,800
and runs that to help with
our directory services

97
00:05:21,780 --> 00:05:24,720
and the information about
users and computers.

98
00:05:24,720 --> 00:05:28,350
So to take a look at that, we
can do a couple things here.

99
00:05:28,350 --> 00:05:29,670
We can go to Tools

100
00:05:29,670 --> 00:05:33,420
and we can go to all the
Active Directory snap-ins

101
00:05:33,420 --> 00:05:36,480
that we have here or console
Windows that we have here.

102
00:05:36,480 --> 00:05:39,303
For example, Active Directory
Users and Computers.

103
00:05:41,430 --> 00:05:43,053
And when we bring that up,

104
00:05:44,220 --> 00:05:47,490
we'll see our domain which we created

105
00:05:47,490 --> 00:05:50,820
when we promoted this server
to a domain controller,

106
00:05:50,820 --> 00:05:53,340
when we first created this domain,

107
00:05:53,340 --> 00:05:55,110
and we see all of the objects in here

108
00:05:55,110 --> 00:05:57,693
including computers and especially users.

109
00:05:58,860 --> 00:06:00,870
I like to take these console Windows

110
00:06:00,870 --> 00:06:02,943
and snap them into an MMC.

111
00:06:04,050 --> 00:06:06,970
Which I've already done, created this MMC

112
00:06:07,830 --> 00:06:08,700
and here we have it,

113
00:06:08,700 --> 00:06:11,163
here is the Active Directory
Users and Computers.

114
00:06:12,750 --> 00:06:15,510
And if we open that, we'll see our domain.

115
00:06:15,510 --> 00:06:17,700
And if we open that, we'll
see the same information

116
00:06:17,700 --> 00:06:20,220
that we saw in that console window.

117
00:06:20,220 --> 00:06:23,460
And if we go to Users, we'll
see all the user accounts

118
00:06:23,460 --> 00:06:28,460
and groups of users that are
able to log on to this domain.

119
00:06:29,340 --> 00:06:33,810
User A, user B, user C,
test users, we've got Alice,

120
00:06:33,810 --> 00:06:37,620
we've got all this stuff,
a group called IT 1,

121
00:06:37,620 --> 00:06:39,990
all these are users that have the ability

122
00:06:39,990 --> 00:06:41,430
to log onto the domain.

123
00:06:41,430 --> 00:06:46,430
And this server takes control
of all that authentication,

124
00:06:46,470 --> 00:06:48,870
the username and password process.

125
00:06:48,870 --> 00:06:53,870
It logs who actually
tries to connect and when,

126
00:06:54,420 --> 00:06:55,950
all that good stuff.

127
00:06:55,950 --> 00:06:58,590
We also have our computers
that are allowed to connect.

128
00:06:58,590 --> 00:07:01,170
For example, this laptop
and this virtual machine,

129
00:07:01,170 --> 00:07:03,360
and this NAS box, they are all allowed

130
00:07:03,360 --> 00:07:05,640
to connect into this domain.

131
00:07:05,640 --> 00:07:09,360
So the LDAP protocol
takes care of all this.

132
00:07:09,360 --> 00:07:14,360
It allows us to keep all this information

133
00:07:15,300 --> 00:07:17,103
in an organized fashion.

134
00:07:18,270 --> 00:07:20,790
That's all part of Directory Services.

135
00:07:20,790 --> 00:07:22,620
It's all part of Active Directory.

136
00:07:22,620 --> 00:07:24,360
In Windows Server that's been promoted

137
00:07:24,360 --> 00:07:25,743
to a domain controller.

138
00:07:27,270 --> 00:07:28,930
Let's go to our PowerShell here

139
00:07:31,620 --> 00:07:33,000
and we'll run a couple commands.

140
00:07:33,000 --> 00:07:38,000
First, we'll run the netstat-n command.

141
00:07:39,750 --> 00:07:44,610
And you'll see the
sessions that are running,

142
00:07:44,610 --> 00:07:49,610
the established sessions running
within TCP on this system.

143
00:07:51,300 --> 00:07:55,440
One of those is LDAP

144
00:07:55,440 --> 00:07:57,423
which runs on port 389.

145
00:07:59,310 --> 00:08:02,430
It's internal, it's the same IP address

146
00:08:02,430 --> 00:08:05,850
for the local and the foreign
but that is established.

147
00:08:05,850 --> 00:08:09,450
That is something that is
running on this system.

148
00:08:09,450 --> 00:08:11,910
It has to be running,
LDAP has to be running

149
00:08:11,910 --> 00:08:15,840
on port 389 in order to allow

150
00:08:15,840 --> 00:08:20,673
for Active Directory connections
and user log-ons and so on.

151
00:08:21,570 --> 00:08:25,710
Now, if we do a netstat-an,

152
00:08:25,710 --> 00:08:29,040
we'll get all the
information, TCP and UDP,

153
00:08:29,040 --> 00:08:34,040
which I'm gonna break out
of and scroll back up here

154
00:08:34,260 --> 00:08:38,170
and this will show not only
the established connections

155
00:08:39,450 --> 00:08:42,000
like 389 here, LDAP,

156
00:08:42,000 --> 00:08:45,510
but also anything that is listening,

157
00:08:45,510 --> 00:08:48,210
any protocols that are
running that are listening

158
00:08:48,210 --> 00:08:49,890
and ready for connections.

159
00:08:49,890 --> 00:08:54,890
For example Kerberos on port
88 which we can make use of

160
00:08:55,050 --> 00:08:58,440
in Windows Server domain
controllers as well.

161
00:08:58,440 --> 00:09:00,330
So both of those are actually installed.

162
00:09:00,330 --> 00:09:03,690
Those protocols are installed
when we promote this server

163
00:09:03,690 --> 00:09:07,200
to a domain controller
which is just one example

164
00:09:07,200 --> 00:09:10,140
of an authentication server.

165
00:09:10,140 --> 00:09:12,930
Now, authentication
servers can also be used

166
00:09:12,930 --> 00:09:15,210
for connecting over a VPN.

167
00:09:15,210 --> 00:09:17,610
For example, if there's
users out on the internet

168
00:09:17,610 --> 00:09:20,730
and they wanna connect
securely through VPN,

169
00:09:20,730 --> 00:09:23,880
a Virtual Private Network,
through to our router

170
00:09:23,880 --> 00:09:28,050
or firewall or whatever
device and get into our LAN

171
00:09:28,050 --> 00:09:31,773
to try to log in or get access
to servers or who knows what.

172
00:09:32,640 --> 00:09:35,580
And there are some examples
of authentication servers

173
00:09:35,580 --> 00:09:40,323
that can be used for that,
for example RADIUS and TACACS.

174
00:09:41,430 --> 00:09:43,710
So there are a variety

175
00:09:43,710 --> 00:09:47,310
of different authentication
servers available

176
00:09:47,310 --> 00:09:51,090
but the A+ exams will focus the most

177
00:09:51,090 --> 00:09:55,503
on domain controllers in
Windows-based networks.
