%% You should probably cite draft-ietf-kitten-krb-spake-preauth instead of this I-D. @techreport{mccallum-kitten-krb-spake-preauth-00, number = {draft-mccallum-kitten-krb-spake-preauth-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-mccallum-kitten-krb-spake-preauth/00/}, author = {Nathaniel McCallum}, title = {{SPAKE Pre-Authentication}}, pagetotal = 11, year = 2015, month = apr, day = 25, abstract = {This document defines a new password authenticated key exchange based pre-authentication mechanism for performing Kerberos authentication. This mechanism has three goals. First, it makes Kerberos pre- authentication more resilient against time synchronization errors by removing the need to transfer an encrypted timestamp. Second, it increases the security of the Kerberos pre-authentication exchange by making offline brute-force attacks impossible. Third, it enables the use of secure second factor authentication without FAST by utilizing the existing trust relationship established by the shared first factor.}, }