Skip to main content
Engineering, Backend, Security

Automating Kerberos Keytab Rotation at Uber

June 18 / Global
Featured image for Automating Kerberos Keytab Rotation at Uber
Image
Figure 1: Keytab architecture.
Image
Figure 2: Kerberos protocol.
Image
Figure 3: Timeline of keytab rotation during AS_REQ.
Image
Figure 4: Timeline of keytab rotation during AP_REQ.
Image
Figure 5: Rate limit config.
Image
Figure 6: Allowlist and rate-limit config.
Junyan Guo

Junyan Guo

Junyan Guo is a Senior Software Engineer on the Data Security team at Uber. He currently leads development on Uber’s Kerberos infrastructure and also works on AI Security and Compliance at Uber.

Matt Mathew

Matt Mathew

Matt is a Sr. Staff Engineer on the Engineering Security team at Uber. He currently works on various projects in the security domain. Previously, he led the initiative to containerize and automate Data infrastructure at Uber.

Posted by Junyan Guo, Matt Mathew