RFC 5801: Using Generic Security Service Application Program Interface (GSS-API) Mechanisms in Simple Authentication and Security Layer (SASL): The GS2 Mechanism Family
In plain English — editorial summary, not part of the RFC
This document describes how to use a Generic Security Service Application Program Interface (GSS-API) mechanism in the Simple Authentication and Security Layer (SASL) framework. This is done by defining a new SASL mechanism family, called GS2. This mechanism family offers a number of improvements over the previous "SASL/ GSSAPI" mechanism: it is more general, uses fewer messages for the authentication phase in some cases, and supports negotiable use of channel binding. Only GSS-API mechanisms that support channel binding and mutual authentication are supported. [STANDARDS-TRACK]
Document record
- Document ID
- RFC5801
- Published
- July 2010
- Authors
- S. Josefsson; N. Williams
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 26
- Also known as
- —
- Updated by:
- RFC 9266
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 5802Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API MechanismsUpdated
July 2010
- RFC 5793PB-TNC: A Posture Broker (PB) Protocol Compatible with Trusted Network Connect (TNC)Current
March 2010
- RFC 5792PA-TNC: A Posture Attribute (PA) Protocol Compatible with Trusted Network Connect (TNC)Current
March 2010
- RFC 5816ESSCertIDv2 Update for RFC 3161Current
April 2010
- RFC 5776Use of Timed Efficient Stream Loss-Tolerant Authentication (TESLA) in the Asynchronous Layered Coding (ALC) and NACK-Oriented Reliable Multicast (NORM) ProtocolsCurrent
April 2010
- RFC 5836Extensible Authentication Protocol (EAP) Early Authentication Problem StatementCurrent
April 2010
- RFC 5840Wrapped Encapsulating Security Payload (ESP) for Traffic VisibilityCurrent
April 2010
- RFC 5758Internet X.509 Public Key Infrastructure: Additional Algorithms and Identifiers for DSA and ECDSACurrent
January 2010
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?