The Kerberos Version 5 Generic Security Service Application Program Interface Mechanism: Version 2
RFC 4121, “The Kerberos Version 5 Generic Security Service Application Program Interface Mechanism: Version 2”, is a Proposed Standard document published in July 2005 by L. Zhu, K. Jaganathan, S. Hartman. It updates RFC 1964. It has since been updated by RFC 5896, RFC 6112, RFC 6542, RFC 6649, RFC 8062. The canonical text is published by the RFC Editor.
Abstract
This document defines protocols, procedures, and conventions to be employed by peers implementing the Generic Security Service Application Program Interface (GSS-API) when using the Kerberos Version 5 mechanism.
RFC 1964 is updated and incremental changes are proposed in response to recent developments such as the introduction of Kerberos cryptosystem framework. These changes support the inclusion of new cryptosystems, by defining new per-message tokens along with their encryption and checksum algorithms based on the cryptosystem profiles. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 4121 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4120 The Kerberos Network Authentication Service
- RFC 4122 A Universally Unique IDentifier URN Namespace
- RFC 4119 A Presence-based GEOPRIV Location Object Format
- RFC 4123 Session Initiation Protocol -H.323 Interworking Requirements
- RFC 4118 Architecture Taxonomy for Control and Provisioning of Wireless Access Points
- RFC 4124 Protocol Extensions for Support of Diffserv-aware MPLS Traffic Engineering
- RFC 4117 Transcoding Services Invocation in the Session Initiation Protocol Using Third Party Call Control
- RFC 4125 Maximum Allocation Bandwidth Constraints Model for Diffserv-aware MPLS Traffic Engineering