Skip to main content

The Hashed Token SASL Mechanism
draft-schmaus-kitten-sasl-ht-10

Document Type Replaced Internet-Draft (kitten WG)
Expired & archived
Authors Florian Schmaus , Christoph Egger
Last updated 2025-02-20 (Latest revision 2025-01-30)
Replaced by draft-ietf-kitten-sasl-ht
RFC stream Internet Engineering Task Force (IETF)
Intended RFC status (None)
Formats
Additional resources GitHub Repository
Mailing list discussion
Stream WG state Adopted by a WG
Document shepherd (None)
IESG IESG state Replaced by draft-ietf-kitten-sasl-ht
Consensus boilerplate Unknown
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

This document specifies the family of Hashed Token SASL mechanisms which enable a proof-of-possession-based authentication scheme and are meant to be used to quickly re-authenticate of a previous session. The Hashed Token SASL mechanism's authentication sequence consists of only one round-trip. The usage of short-lived, exclusively ephemeral hashed tokens is achieving the single round- trip property. The SASL mechanism specified herein further provides hash agility, mutual authentication and support for channel binding.

Authors

Florian Schmaus
Christoph Egger

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)