Desired Enhancements to Generic Security Services Application Program Interface Version 3 Naming
RFC 4768, “Desired Enhancements to Generic Security Services Application Program Interface Version 3 Naming”, is an Informational document published in December 2006 by S. Hartman. The canonical text is published by the RFC Editor.
Abstract
The Generic Security Services API (GSS-API) provides a naming architecture that supports name-based authorization. GSS-API authenticates two named parties to each other. Names can be stored on access control lists (ACLs) to make authorization decisions. Advances in security mechanisms and the way implementers wish to use GSS-API require this model to be extended for the next version of GSS-API. As people move within an organization or change their names, the name authenticated by GSS-API may change. Using some sort of constant identifier would make ACLs more stable. Some mechanisms, such as public-key mechanisms, do not have a single name to be used across all environments. Other mechanisms, such as Kerberos, may include group membership or role information as part of authentication. This document motivates extensions to GSS-API naming and describes the extensions under discussion. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 4768 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4769 IANA Registration for an Enumservice Containing Public Switched Telephone Network Signaling Information
- RFC 4772 Security Implications of Using the Data Encryption Standard
- RFC 4763 Extensible Authentication Protocol Method for Shared-secret Authentication and Key Establishment
- RFC 4773 Administration of the IANA Special Purpose IPv6 Address Block
- RFC 4774 Specifying Alternate Semantics for the Explicit Congestion Notification Field
- RFC 4775 Procedures for Protocol Extensions and Variations
- RFC 4776 Dynamic Host Configuration Protocol Option for Civic Addresses Configuration Information
- RFC 4759 The ENUM Dip Indicator Parameter for the "tel" URI