Kerberos Version 5 Generic Security Service Application Program Interface Channel Binding Hash Agility
RFC 6542, “Kerberos Version 5 Generic Security Service Application Program Interface Channel Binding Hash Agility”, is a Proposed Standard document published in March 2012 by S. Emery. It updates RFC 4121. The canonical text is published by the RFC Editor.
Abstract
Currently, channel bindings are implemented using an MD5 hash in the Kerberos Version 5 Generic Security Service Application Programming Interface (GSS-API) mechanism (RFC 4121). This document updates RFC 4121 to allow channel bindings using algorithms negotiated based on Kerberos crypto framework as defined in RFC 3961. In addition, because this update makes use of the last extensible field in the Kerberos client-server exchange message, extensions are defined to allow future protocol extensions. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 6542 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6541 DomainKeys Identified Mail Authorized Third-Party Signatures
- RFC 6543 Reserved IPv6 Interface Identifier for Proxy Mobile IPv6
- RFC 6540 IPv6 Support Required for All IP-Capable Nodes
- RFC 6544 TCP Candidates with Interactive Connectivity Establishment
- RFC 6539 IBAKE: Identity-Based Authenticated Key Exchange
- RFC 6545 Real-time Inter-network Defense
- RFC 6538 The Host Identity Protocol Experiment Report
- RFC 6546 Transport of Real-time Inter-network Defense Messages over HTTP/TLS