RFC 4013: SASLprep: Stringprep Profile for User Names and Passwords
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 7613.
Current document in this lineage: RFC 8265 — Preparation, Enforcement, and Comparison of Internationalized Strings Representing Usernames and Passwords
In plain English — editorial summary, not part of the RFC
This document describes how to prepare Unicode strings representing user names and passwords for comparison. The document defines the "SASLprep" profile of the "stringprep" algorithm to be used for both user names and passwords. This profile is intended to be used by Simple Authentication and Security Layer (SASL) mechanisms (such as PLAIN, CRAM-MD5, and DIGEST-MD5), as well as other protocols exchanging simple user names and/or passwords. [STANDARDS-TRACK]
Document record
- Document ID
- RFC4013
- Published
- March 2005
- Authors
- K. Zeilenga
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 6
- Also known as
- —
- Obsoleted by:
- RFC 7613
Topics
Standards lineage
This document is one revision in a chain of 3 RFCs, each formally replacing the one before it.
- RFC 4013 (2005)
- RFC 7613 (2015)
- RFC 8265 (2017) ✓
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4643Network News Transfer Protocol (NNTP) Extension for AuthenticationCurrent
October 2006
- RFC 5803Lightweight Directory Access Protocol (LDAP) Schema for Storing Salted Challenge Response Authentication Mechanism (SCRAM) SecretsCurrent
July 2010
- RFC 4422Simple Authentication and Security Layer (SASL)Current
June 2006
- RFC 4752The Kerberos V5 ("GSSAPI") Simple Authentication and Security Layer (SASL) MechanismCurrent
November 2006
- RFC 2831Using Digest Authentication as a SASL MechanismObsoleted
May 2000
- RFC 5802Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API MechanismsUpdated
July 2010
- RFC 7804Salted Challenge Response HTTP Authentication MechanismCurrent
March 2016
- RFC 7832Application Bridging for Federated Access Beyond Web (ABFAB) Use CasesCurrent
May 2016
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?