Name Attributes for the GSS-API Extensible Authentication Protocol Mechanism
RFC 7056, “Name Attributes for the GSS-API Extensible Authentication Protocol Mechanism”, is a Proposed Standard document published in December 2013 by S. Hartman, J. Howlett. The canonical text is published by the RFC Editor.
Abstract
The naming extensions to the Generic Security Service Application Programming Interface (GSS-API) provide a mechanism for applications to discover authorization and personalization information associated with GSS-API names. The Extensible Authentication Protocol GSS-API mechanism allows an Authentication, Authorization, and Accounting (AAA) peer to provide authorization attributes alongside an authentication response. It also supplies mechanisms to process Security Assertion Markup Language (SAML) messages provided in the AAA response. This document describes how to use the Naming Extensions API to access that information.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7056 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7055 A GSS-API Mechanism for the Extensible Authentication Protocol
- RFC 7057 Update to the Extensible Authentication Protocol Applicability Statement for Application Bridging for Federated Access Beyond Web
- RFC 7054 Addressing Requirements and Design Considerations for Per-Interface Maintenance Entity Group Intermediate Points
- RFC 7058 Media Control Channel Framework Call Flow Examples
- RFC 7053 SACK-IMMEDIATELY Extension for the Stream Control Transmission Protocol
- RFC 7059 A Comparison of IPv6-over-IPv4 Tunnel Mechanisms
- RFC 7052 Locator/ID Separation Protocol MIB
- RFC 7060 Using LDP Multipoint Extensions on Targeted LDP Sessions