RFC 8009: AES Encryption with HMAC-SHA2 for Kerberos 5
In plain English — editorial summary, not part of the RFC
This document specifies two encryption types and two corresponding checksum types for Kerberos 5. The new types use AES in CTS mode (CBC mode with ciphertext stealing) for confidentiality and HMAC with a SHA-2 hash for integrity.
Document record
- Document ID
- RFC8009
- Published
- October 2016
- Authors
- M. Jenkins; M. Peck; K. Burgin
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- sec
- Pages
- 19
- Also known as
- —
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8019Protecting Internet Key Exchange Protocol Version 2 (IKEv2) Implementations from Distributed Denial-of-Service AttacksCurrent
November 2016
- RFC 8031Curve25519 and Curve448 for the Internet Key Exchange Protocol Version 2 (IKEv2) Key AgreementCurrent
December 2016
- RFC 8037CFRG Elliptic Curve Diffie-Hellman (ECDH) and Signatures in JSON Object Signing and Encryption (JOSE)Updated
January 2017
- RFC 8044Data Types in RADIUSCurrent
January 2017
- RFC 8045RADIUS Extensions for IP Port Configuration and ReportingCurrent
January 2017
- RFC 7970The Incident Object Description Exchange Format Version 2Current
November 2016
- RFC 8053HTTP Authentication Extensions for Interactive ClientsCurrent
January 2017
- RFC 8062Anonymity Support for KerberosCurrent
February 2017
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?