Kerberos Authorization Data Container Authenticated by Multiple Message Authentication Codes
RFC 7751, “Kerberos Authorization Data Container Authenticated by Multiple Message Authentication Codes”, is a Proposed Standard document published in March 2016 by S. Sorce, T. Yu. It updates RFC 4120. The canonical text is published by the RFC Editor.
Abstract
This document specifies a Kerberos authorization data container that supersedes AD-KDC-ISSUED. It allows for multiple Message Authentication Codes (MACs) or signatures to authenticate the contained authorization data elements. The multiple MACs are needed to mitigate shortcomings in the existing AD-KDC-ISSUED container. This document updates RFC 4120.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7751 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7750 Differentiated Service Code Point and Explicit Congestion Notification Monitoring in the Two-Way Active Measurement Protocol
- RFC 7752 North-Bound Distribution of Link-State and Traffic Engineering Information Using BGP
- RFC 7749 The "xml2rfc" Version 2 Vocabulary
- RFC 7753 Port Control Protocol Extension for Port-Set Allocation
- RFC 7748 Elliptic Curves for Security
- RFC 7754 Technical Considerations for Internet Service Blocking and Filtering
- RFC 7747 Basic BGP Convergence Benchmarking Methodology for Data-Plane Convergence
- RFC 7755 SIIT-DC: Stateless IP/ICMP Translation for IPv6 Data Center Environments