RFC 8070: Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) Freshness Extension
In plain English — editorial summary, not part of the RFC
This document describes how to further extend the Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) extension (defined in RFC 4556) to exchange an opaque data blob that a Key Distribution Center (KDC) can validate to ensure that the client is currently in possession of the private key during a PKINIT Authentication Service (AS) exchange.
Document record
- Document ID
- RFC8070
- Published
- February 2017
- Authors
- M. Short; S. Moore; P. Miller
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 9
- Also known as
- —
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8062Anonymity Support for KerberosCurrent
February 2017
- RFC 8080Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSECCurrent
February 2017
- RFC 8053HTTP Authentication Extensions for Interactive ClientsCurrent
January 2017
- RFC 8045RADIUS Extensions for IP Port Configuration and ReportingCurrent
January 2017
- RFC 8044Data Types in RADIUSCurrent
January 2017
- RFC 8037CFRG Elliptic Curve Diffie-Hellman (ECDH) and Signatures in JSON Object Signing and Encryption (JOSE)Updated
January 2017
- RFC 8103Using ChaCha20-Poly1305 Authenticated Encryption in the Cryptographic Message Syntax (CMS)Current
February 2017
- RFC 8031Curve25519 and Curve448 for the Internet Key Exchange Protocol Version 2 (IKEv2) Key AgreementCurrent
December 2016
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?