Kerberos Principal Name Canonicalization and Cross-Realm Referrals
RFC 6806, “Kerberos Principal Name Canonicalization and Cross-Realm Referrals”, is a Proposed Standard document published in November 2012 by S. Hartman, K. Raeburn, L. Zhu. It updates RFC 4120. The canonical text is published by the RFC Editor.
Abstract
This memo documents a method for a Kerberos Key Distribution Center (KDC) to respond to client requests for Kerberos tickets when the client does not have detailed configuration information on the realms of users or services. The KDC will handle requests for principals in other realms by returning either a referral error or a cross-realm Ticket-Granting Ticket (TGT) to another realm on the referral path. The clients will use this referral information to reach the realm of the target principal and then receive the ticket. This memo also provides a mechanism for verifying that a request has not been tampered with in transit. This memo updates RFC 4120. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 6806 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6805 The Application of the Path Computation Element Architecture to the Determination of a Sequence of Domains in MPLS and GMPLS
- RFC 6807 Population Count Extensions to Protocol Independent Multicast
- RFC 6804 DISCOVER: Supporting Multicast DNS Queries
- RFC 6808 Test Plan and Results Supporting Advancement of RFC 2679 on the Standards Track
- RFC 6803 Camellia Encryption for Kerberos 5
- RFC 6809 Mechanism to Indicate Support of Features and Capabilities in the Session Initiation Protocol
- RFC 6802 Ericsson Two-Way Active Measurement Protocol Value-Added Octets
- RFC 6801 Pseudo Content Delivery Protocol for Protecting Multiple Source Flows in the Forward Error Correction Framework