RFC 4178 · PROPOSED STANDARD · 2005

The Simple and Protected Generic Security Service Application Program Interface Negotiation Mechanism

Overview

RFC 4178, “The Simple and Protected Generic Security Service Application Program Interface Negotiation Mechanism”, is a Proposed Standard document published in October 2005 by L. Zhu, P. Leach, K. Jaganathan, W. Ingersoll. It obsoletes RFC 2478. The canonical text is published by the RFC Editor.

Abstract

This document specifies a negotiation mechanism for the Generic Security Service Application Program Interface (GSS-API), which is described in RFC 2743. GSS-API peers can use this negotiation mechanism to choose from a common set of security mechanisms. If per-message integrity services are available on the established mechanism context, then the negotiation is protected against an attacker that forces the selection of a mechanism not desired by the peers.

This mechanism replaces RFC 2478 in order to fix defects in that specification and to describe how to inter-operate with implementations of that specification that are commonly deployed on the Internet. [STANDARDS-TRACK]

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 4178 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
This RFC obsoletes
RFC 2478
Other RFCs from 2005