RFC 4120: The Kerberos Network Authentication Service (V5)
In plain English — editorial summary, not part of the RFC
This document provides an overview and specification of Version 5 of the Kerberos protocol, and it obsoletes RFC 1510 to clarify aspects of the protocol and its intended use that require more detailed or clearer explanation than was provided in RFC 1510. This document is intended to provide a detailed description of the protocol, suitable for implementation, together with descriptions of the appropriate use of protocol messages and fields within those messages. [STANDARDS-TRACK]
Document record
- Document ID
- RFC4120
- Published
- July 2005
- Authors
- C. Neuman; T. Yu; S. Hartman; K. Raeburn
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 138
- Also known as
- —
- Obsoletes:
- RFC 1510
Topics
Standards lineage
This document is one revision in a chain of 3 RFCs, each formally replacing the one before it.
- RFC 1510 (1993)
- RFC 4120 (2005)
- RFC 6649 (2012) ✓
Referenced by
13 later RFCs formally update or obsolete part of this document.
- RFC 4537Kerberos Cryptosystem Negotiation ExtensionCurrent
June 2006
- RFC 5021Extended Kerberos Version 5 Key Distribution Center (KDC) Exchanges over TCPCurrent
August 2007
- RFC 5896Generic Security Service Application Program Interface (GSS-API): Delegate if Approved by PolicyCurrent
June 2010
- RFC 6111Additional Kerberos Naming ConstraintsCurrent
April 2011
- RFC 6112Anonymity Support for KerberosObsoleted
April 2011
- RFC 6113A Generalized Framework for Kerberos Pre-AuthenticationCurrent
April 2011
- RFC 6649Deprecate DES, RC4-HMAC-EXP, and Other Weak Cryptographic Algorithms in KerberosCurrent
July 2012
- RFC 6806Kerberos Principal Name Canonicalization and Cross-Realm ReferralsCurrent
November 2012
- RFC 7751Kerberos Authorization Data Container Authenticated by Multiple Message Authentication Codes (MACs)Current
March 2016
- RFC 8062Anonymity Support for KerberosCurrent
February 2017
- RFC 8129Authentication Indicator in Kerberos TicketsCurrent
March 2017
- RFC 8429Deprecate Triple-DES (3DES) and RC4 in KerberosCurrent
October 2018
- RFC 8553DNS Attrleaf Changes: Fixing Specifications That Use Underscored Node NamesCurrent
March 2019
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 5403RPCSEC_GSS Version 2Updated
February 2009
- RFC 4178The Simple and Protected Generic Security Service Application Program Interface (GSS-API) Negotiation MechanismCurrent
October 2005
- RFC 4211Internet X.509 Public Key Infrastructure Certificate Request Message Format (CRMF)Updated
September 2005
- RFC 4302IP Authentication HeaderCurrent
December 2005
- RFC 4303IP Encapsulating Security Payload (ESP)Current
December 2005
- RFC 4305Cryptographic Algorithm Implementation Requirements for Encapsulating Security Payload (ESP) and Authentication Header (AH)Obsoleted
December 2005
- RFC 4306Internet Key Exchange (IKEv2) ProtocolObsoleted
December 2005
- RFC 4505Anonymous Simple Authentication and Security Layer (SASL) MechanismCurrent
June 2006
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?