Public Key Cryptography for Initial Authentication in Kerberos
RFC 4556, “Public Key Cryptography for Initial Authentication in Kerberos”, is a Proposed Standard document published in June 2006 by L. Zhu, B. Tung. It has since been updated by RFC 6112, RFC 8062, RFC 8636. The canonical text is published by the RFC Editor.
Abstract
This document describes protocol extensions (hereafter called PKINIT) to the Kerberos protocol specification. These extensions provide a method for integrating public key cryptography into the initial authentication exchange, by using asymmetric-key signature and/or encryption algorithms in pre-authentication data fields. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 4556 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4555 IKEv2 Mobility and Multihoming Protocol
- RFC 4557 Online Certificate Status Protocol Support for Public Key Cryptography for Initial Authentication in Kerberos
- RFC 4554 Use of VLANs for IPv4-IPv6 Coexistence in Enterprise Networks
- RFC 4558 Node-ID Based Resource Reservation Protocol Hello: A Clarification Statement
- RFC 4553 Structure-Agnostic Time Division Multiplexing over Packet
- RFC 4559 SPNEGO-based Kerberos and NTLM HTTP Authentication in Microsoft Windows
- RFC 4552 Authentication/Confidentiality for OSPFv3
- RFC 4560 Definitions of Managed Objects for Remote Ping, Traceroute, and Lookup Operations