Issues in Identifier Comparison for Security Purposes
RFC 6943, “Issues in Identifier Comparison for Security Purposes”, is an Informational document published in May 2013 by D. Thaler. The canonical text is published by the RFC Editor.
Abstract
Identifiers such as hostnames, URIs, IP addresses, and email addresses are often used in security contexts to identify security principals and resources. In such contexts, an identifier presented via some protocol is often compared using some policy to make security decisions such as whether the security principal may access the resource, what level of authentication or encryption is required, etc. If the parties involved in a security decision use different algorithms to compare identifiers, then failure scenarios ranging from denial of service to elevation of privilege can result. This document provides a discussion of these issues that designers should consider when defining identifiers and protocols, and when constructing architectures that use multiple protocols.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 6943 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6942 Diameter Support for the EAP Re-authentication Protocol
- RFC 6944 Applicability Statement: DNS Security DNSKEY Algorithm Implementation Status
- RFC 6941 MPLS Transport Profile Security Framework
- RFC 6945 Definitions of Managed Objects for the Resource Public Key Infrastructure to Router Protocol
- RFC 6946 Processing of IPv6 "Atomic" Fragments
- RFC 6939 Client Link-Layer Address Option in DHCPv6
- RFC 6947 The Session Description Protocol Alternate Connectivity Attribute
- RFC 6938 Deprecation of BGP Path Attributes: DPA, ADVERTISER, and RCID_PATH / CLUSTER_ID