@techreport{ietf-cat-kerberos-err-msg-00, number = {draft-ietf-cat-kerberos-err-msg-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-cat-kerberos-err-msg/00/}, author = {Gene Tsudik and Brian Tung and Matt Hur and Ari Medvinsky}, title = {{Integrity Protection for the Kerberos Error Message}}, pagetotal = 4, year = 1997, month = mar, day = 26, abstract = {The Kerberos error message, as defined in RFC 1510, is transmitted to the client without any integrity assurance. Therefore, the client has no means to distinguish between a valid error message sent from the KDC and one sent by an attacker. This draft describes a method for assuring the integrity of Kerberos error messages, and proposes a consistent format for the e-data field in the KRB\_ERROR message. This e-data format enables the storage of cryptographic checksums by providing an extensible mechanism for specifying e-data types.}, }