RFC 6113: A Generalized Framework for Kerberos Pre-Authentication
In plain English — editorial summary, not part of the RFC
Kerberos is a protocol for verifying the identity of principals (e.g., a workstation user or a network server) on an open network. The Kerberos protocol provides a facility called pre-authentication. Pre-authentication mechanisms can use this facility to extend the Kerberos protocol and prove the identity of a principal. This document describes a more formal model for this facility. The model describes what state in the Kerberos request a pre-authentication mechanism is likely to change. It also describes how multiple pre-authentication mechanisms used in the same request will interact. This document also provides common tools needed by multiple pre-authentication mechanisms. One of these tools is a secure channel between the client and the key distribution center with a reply key strengthening mechanism; this secure channel can be used to protect the authentication exchange and thus eliminate offline dictionary attacks. With these tools, it is relatively straightforward to chain multiple authentication mechanisms, utilize a different key management system, or support a new key agreement algorithm. [STANDARDS-TRACK]
Document record
- Document ID
- RFC6113
- Published
- April 2011
- Authors
- S. Hartman; L. Zhu
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 48
- Also known as
- —
- Updates:
- RFC 4120
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6112Anonymity Support for KerberosObsoleted
April 2011
- RFC 6111Additional Kerberos Naming ConstraintsCurrent
April 2011
- RFC 6071IP Security (IPsec) and Internet Key Exchange (IKE) Document RoadmapCurrent
February 2011
- RFC 6158RADIUS Design GuidelinesUpdated
March 2011
- RFC 6066Transport Layer Security (TLS) Extensions: Extension DefinitionsUpdated
January 2011
- RFC 6063Dynamic Symmetric Key Provisioning Protocol (DSKPP)Current
December 2010
- RFC 6170Internet X.509 Public Key Infrastructure -- Certificate ImageObsoleted
May 2011
- RFC 6054Using Counter Modes with Encapsulating Security Payload (ESP) and Authentication Header (AH) to Protect Group TrafficCurrent
November 2010
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?