Generic Security Service Application Program Interface : Delegate if Approved by Policy
RFC 5896, “Generic Security Service Application Program Interface : Delegate if Approved by Policy”, is a Proposed Standard document published in June 2010 by L. Hornquist Astrand, S. Hartman. It updates RFC 2743, RFC 2744, RFC 4120, RFC 4121. The canonical text is published by the RFC Editor.
Abstract
Several Generic Security Service Application Program Interface (GSS-API) applications work in a multi-tiered architecture, where the server takes advantage of delegated user credentials to act on behalf of the user and contact additional servers. In effect, the server acts as an agent on behalf of the user. Examples include web applications that need to access e-mail or file servers, including CIFS (Common Internet File System) file servers. However, delegating the user credentials to a party who is not sufficiently trusted is problematic from a security standpoint. Kerberos provides a flag called OK-AS-DELEGATE that allows the administrator of a Kerberos realm to communicate that a particular service is trusted for delegation. This specification adds support for this flag and similar facilities in other authentication mechanisms to GSS-API (RFC 2743). [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5896 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5895 Mapping Characters for Internationalized Domain Names in Applications 2008
- RFC 5897 Identification of Communications Services in the Session Initiation Protocol
- RFC 5894 Internationalized Domain Names for Applications : Background, Explanation, and Rationale
- RFC 5898 Connectivity Preconditions for Session Description Protocol Media Streams
- RFC 5893 Right-to-Left Scripts for Internationalized Domain Names for Applications
- RFC 5892 The Unicode Code Points and Internationalized Domain Names for Applications
- RFC 5891 Internationalized Domain Names in Applications : Protocol
- RFC 5901 Extensions to the IODEF-Document Class for Reporting Phishing