# Kerberos & step-up mechanism

**URL:** <https://forum.keycloak.org/t/kerberos-step-up-mechanism/16432>\
**Category:** Extending the server\
**Created:** [July 13, 2022, 12:47pm UTC](https://forum.keycloak.org/t/kerberos-step-up-mechanism/16432 "2022-07-13T12:47:32Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![jermarchand](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/jermarchand/32/6171_2.png) [@jermarchand](https://forum.keycloak.org/u/jermarchand)\
**Post date:** [July 13, 2022, 12:47pm UTC](https://forum.keycloak.org/t/kerberos-step-up-mechanism/16432/1 "2022-07-13T12:47:32Z")

</div>

Hi,

In the documentation, the browser flow to step-up is : [Server Administration Guide](https://www.keycloak.org/docs/latest/server_admin/index.html#_step-up-flow)

It work fine because the “CookieAuthenticator” take into account the LoA.

> <https://github.com/keycloak/keycloak/blob/main/services/src/main/java/org/keycloak/authentication/authenticators/browser/CookieAuthenticator.java#L65>

The “SpnegoAuthenticator” don’t check the LoA ☹

Before submit a PR, I’m asking me if I miss something in the concepts or the documentation.

Thanks for your comments,

Br,
