Initial and Pass Through Authentication Using Kerberos V5 and the GSS- API (IAKERB)
draft-ietf-kitten-iakerb-03
Document | Type | Expired Internet-Draft (kitten WG) | |
---|---|---|---|
Last updated | 2017-10-01 (latest revision 2017-03-30) | ||
Replaces | draft-ietf-krb-wg-iakerb | ||
Stream | IETF | ||
Intended RFC status | (None) | ||
Formats |
Expired & archived
plain text
pdf
html
bibtex
|
||
Stream | WG state | WG Document | |
Document shepherd | No shepherd assigned | ||
IESG | IESG state | Expired | |
Consensus Boilerplate | Unknown | ||
Telechat date | |||
Responsible AD | (None) | ||
Send notices to | (None) |
https://www.ietf.org/archive/id/draft-ietf-kitten-iakerb-03.txt
Abstract
This document defines extensions to the Kerberos protocol and the GSS-API Kerberos mechanism that enable a GSS-API Kerberos client to exchange messages with the KDC by using the GSS-API acceptor as a proxy, encapsulating the Kerberos messages inside GSS-API tokens. With these extensions a client can obtain Kerberos tickets for services where the KDC is not accessible to the client, but is accessible to the application server.
Authors
Benjamin Kaduk
(kaduk@mit.edu)
Jim Schaad
(ietf@augustcellars.com)
Larry Zhu
(lzhu@microsoft.com)
Jeffrey Altman
(jaltman@secure-endpoints.com)
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)