This Internet-Draft is no longer active. Unofficial copies of old Internet-Drafts can be found here:
http://tools.ietf.org/id/draft-perez-abfab-eap-gss-preauth.
Abstract:
This draft defines an alternative to the standard cross-realm
operation in Kerberos, to allow users from an organization can obtain
a TGT from the KDC of a different one, both belonging to the same
AAA-based federation. This proposal makes use of the GSS-API pre-
authentication for Kerberos and the GSS-API Mechanism for the
Extensible Authentication Protocol to carry out the required
functionality.
Authors:
Alejandro Perez-Mendez <alex@um.es>
Rafael Lopez <rafa@um.es>
Fernando Pereniguez-Garcia <pereniguez@um.es>
Gabriel Lopez-Millan <gabilm@um.es>
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid)