RFC 6943: Issues in Identifier Comparison for Security Purposes
In plain English — editorial summary, not part of the RFC
Identifiers such as hostnames, URIs, IP addresses, and email addresses are often used in security contexts to identify security principals and resources. In such contexts, an identifier presented via some protocol is often compared using some policy to make security decisions such as whether the security principal may access the resource, what level of authentication or encryption is required, etc. If the parties involved in a security decision use different algorithms to compare identifiers, then failure scenarios ranging from denial of service to elevation of privilege can result. This document provides a discussion of these issues that designers should consider when defining identifiers and protocols, and when constructing architectures that use multiple protocols.
Document record
- Document ID
- RFC6943
- Published
- May 2013
- Authors
- D. Thaler
- Status
- INFORMATIONAL
- Stream
- IAB
- Area
- —
- Pages
- 26
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6570URI TemplateCurrent
March 2012
- RFC 5122Internationalized Resource Identifiers (IRIs) and Uniform Resource Identifiers (URIs) for the Extensible Messaging and Presence Protocol (XMPP)Current
February 2008
- RFC 4622Internationalized Resource Identifiers (IRIs) and Uniform Resource Identifiers (URIs) for the Extensible Messaging and Presence Protocol (XMPP)Obsoleted
August 2006
- RFC 6920Naming Things with HashesCurrent
April 2013
- RFC 7284The Profile URI RegistryCurrent
June 2014
- RFC 7565The 'acct' URI SchemeCurrent
May 2015
- RFC 7595Guidelines and Registration Procedures for URI SchemesUpdated
June 2015
- RFC 6270The 'tn3270' URI SchemeCurrent
June 2011
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?