RFC 8636: Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) Algorithm Agility
In plain English — editorial summary, not part of the RFC
This document updates the Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) standard (RFC 4556) to remove protocol structures tied to specific cryptographic algorithms. The PKINIT key derivation function is made negotiable, and the digest algorithms for signing the pre-authentication data and the client's X.509 certificates are made discoverable. These changes provide preemptive protection against vulnerabilities discovered in the future in any specific cryptographic algorithm and allow incremental deployment of newer algorithms.
Document record
- Document ID
- RFC8636
- Published
- July 2019
- Authors
- L. Hornquist Astrand; L. Zhu; M. Cullen; G. Hudson
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 21
- Also known as
- —
- Updates:
- RFC 4556
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8628OAuth 2.0 Device Authorization GrantCurrent
August 2019
- RFC 8649Hash Of Root Key Certificate ExtensionCurrent
August 2019
- RFC 8657Certification Authority Authorization (CAA) Record Extensions for Account URI and Automatic Certificate Management Environment (ACME) Method BindingCurrent
November 2019
- RFC 8659DNS Certification Authority Authorization (CAA) Resource RecordCurrent
November 2019
- RFC 8612DDoS Open Threat Signaling (DOTS) RequirementsCurrent
May 2019
- RFC 8600Using Extensible Messaging and Presence Protocol (XMPP) for Security Information ExchangeCurrent
June 2019
- RFC 8598Split DNS Configuration for the Internet Key Exchange Protocol Version 2 (IKEv2)Current
May 2019
- RFC 8689SMTP Require TLS OptionCurrent
November 2019
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?