<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.williams-kitten-krb5-pkcross" target="https://datatracker.ietf.org/doc/html/draft-williams-kitten-krb5-pkcross-05">
   <front>
      <title>Public Key-Based Kerberos Cross Realm Path Traversal Protocol Using Kerberized Certification Authorities (kx509) and PKINIT</title>
      <author initials="N." surname="Williams" fullname="Nicolás Williams">
         <organization>Cryptonector</organization>
      </author>
      <date month="October" day="27" year="2014" />
      <abstract>
	 <t>   This document specifies a protocol for obtaining cross-realm Kerberos
   tickets using existing, related protocols: kerberized certification
   authorities (kx509) and public key cryptography initial
   authentication in Kerberos (PKINIT).  The resulting protocol has a
   number of desirable properties, primarily that it allows Kerberos to
   scale to large numbers of realms.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-williams-kitten-krb5-pkcross-05" />
   
</reference>
