The Simple and Protected Generic Security Service Application Program Interface Negotiation Mechanism
RFC 4178, “The Simple and Protected Generic Security Service Application Program Interface Negotiation Mechanism”, is a Proposed Standard document published in October 2005 by L. Zhu, P. Leach, K. Jaganathan, W. Ingersoll. It obsoletes RFC 2478. The canonical text is published by the RFC Editor.
Abstract
This document specifies a negotiation mechanism for the Generic Security Service Application Program Interface (GSS-API), which is described in RFC 2743. GSS-API peers can use this negotiation mechanism to choose from a common set of security mechanisms. If per-message integrity services are available on the established mechanism context, then the negotiation is protected against an attacker that forces the selection of a mechanism not desired by the peers.
This mechanism replaces RFC 2478 in order to fix defects in that specification and to describe how to inter-operate with implementations of that specification that are commonly deployed on the Internet. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 4178 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4177 Architectural Approaches to Multi-homing for IPv6
- RFC 4179 Using Universal Content Identifier as Uniform Resource Names
- RFC 4176 Framework for Layer 3 Virtual Private Networks Operations and Management
- RFC 4180 Common Format and MIME Type for Comma-Separated Values Files
- RFC 4175 RTP Payload Format for Uncompressed Video
- RFC 4181 Guidelines for Authors and Reviewers of MIB Documents
- RFC 4174 The IPv4 Dynamic Host Configuration Protocol Option for the Internet Storage Name Service
- RFC 4182 Removing a Restriction on the use of MPLS Explicit NULL