RFC 8353: Generic Security Service API Version 2: Java Bindings Update
In plain English — editorial summary, not part of the RFC
The Generic Security Services Application Programming Interface (GSS-API) offers application programmers uniform access to security services atop a variety of underlying cryptographic mechanisms. This document updates the Java bindings for the GSS-API that are specified in "Generic Security Service API Version 2: Java Bindings Update" (RFC 5653). This document obsoletes RFC 5653 by adding a new output token field to the GSSException class so that when the initSecContext or acceptSecContext methods of the GSSContext class fail, it has a chance to emit an error token that can be sent to the peer for debugging or informational purpose. The stream-based GSSContext methods are also removed in this version. The GSS-API is described at a language-independent conceptual level in "Generic Security Service Application Program Interface Version 2, Update 1" (RFC 2743). The GSS-API allows a caller application to authenticate a principal identity, to delegate rights to a peer, and to apply security services such as confidentiality and integrity on a per-message basis. Examples of security mechanisms defined for GSS-API are "The Simple Public-Key GSS-API Mechanism (SPKM)" (RFC 2025) and "The Kerberos Version 5 Generic Security Service Application Program Interface (GSS-API) Mechanism: Version 2" (RFC 4121).
Document record
- Document ID
- RFC8353
- Published
- May 2018
- Authors
- M. Upadhyay; S. Malkani; W. Wang
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 96
- Also known as
- —
- Obsoletes:
- RFC 5653
Topics
Standards lineage
This document is one revision in a chain of 3 RFCs, each formally replacing the one before it.
- RFC 2853 (2000)
- RFC 5653 (2009)
- RFC 8353 (2018)
Read the full history of Generic Security Service API Version 2: Java Bindings Update →
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8429Deprecate Triple-DES (3DES) and RC4 in KerberosCurrent
October 2018
- RFC 7832Application Bridging for Federated Access Beyond Web (ABFAB) Use CasesCurrent
May 2016
- RFC 7831Application Bridging for Federated Access Beyond Web (ABFAB) ArchitectureCurrent
May 2016
- RFC 7804Salted Challenge Response HTTP Authentication MechanismCurrent
March 2016
- RFC 7546Structure of the Generic Security Service (GSS) Negotiation LoopCurrent
May 2015
- RFC 5588Generic Security Service Application Program Interface (GSS-API) Extension for Storing Delegated CredentialsCurrent
July 2009
- RFC 5587Extended Generic Security Service Mechanism Inquiry APIsCurrent
July 2009
- RFC 5554Clarifications and Extensions to the Generic Security Service Application Program Interface (GSS-API) for the Use of Channel BindingsCurrent
May 2009
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?