RFC 9588: Kerberos Simple Password-Authenticated Key Exchange (SPAKE) Pre-authentication
In plain English — editorial summary, not part of the RFC
This document defines a new pre-authentication mechanism for the Kerberos protocol. The mechanism uses a password-authenticated key exchange (PAKE) to prevent brute-force password attacks, and it may incorporate a second factor.
Document record
- Document ID
- RFC9588
- Published
- August 2024
- Authors
- N. McCallum; S. Sorce; R. Harwood; G. Hudson
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 33
- Also known as
- —
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9593Announcing Supported Authentication Methods in the Internet Key Exchange Protocol Version 2 (IKEv2)Current
July 2024
- RFC 9594Key Provisioning for Group Communication Using Authentication and Authorization for Constrained Environments (ACE)Current
September 2024
- RFC 9580OpenPGPCurrent
July 2024
- RFC 9596CBOR Object Signing and Encryption (COSE) "typ" (type) Header ParameterCurrent
June 2024
- RFC 9597CBOR Web Token (CWT) Claims in COSE HeadersCurrent
June 2024
- RFC 9579Use of Password-Based Message Authentication Code 1 (PBMAC1) in PKCS #12 SyntaxObsoleted
May 2024
- RFC 9578Privacy Pass Issuance ProtocolsCurrent
June 2024
- RFC 9598Internationalized Email Addresses in X.509 CertificatesCurrent
May 2024
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?