Anonymity Support for Kerberos
RFC 8062, “Anonymity Support for Kerberos”, is a Proposed Standard document published in February 2017 by L. Zhu, P. Leach, S. Hartman, S. Emery. It updates RFC 4120, RFC 4121, RFC 4556. It obsoletes RFC 6112. The canonical text is published by the RFC Editor.
Abstract
This document defines extensions to the Kerberos protocol to allow a Kerberos client to securely communicate with a Kerberos application service without revealing its identity, or without revealing more than its Kerberos realm. It also defines extensions that allow a Kerberos client to obtain anonymous credentials without revealing its identity to the Kerberos Key Distribution Center (KDC). This document updates RFCs 4120, 4121, and 4556. This document obsoletes RFC 6112 and reclassifies that document as Historic. RFC 6112 contained errors, and the protocol described in that specification is not interoperable with any known implementation. This specification describes a protocol that interoperates with multiple implementations.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8062 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8061 Locator/ID Separation Protocol Data-Plane Confidentiality
- RFC 8063 Key Relay Mapping for the Extensible Provisioning Protocol
- RFC 8060 LISP Canonical Address Format
- RFC 8064 Recommendation on Stable IPv6 Interface Identifiers
- RFC 8059 PIM Join Attributes for Locator/ID Separation Protocol Environments
- RFC 8065 Privacy Considerations for IPv6 Adaptation-Layer Mechanisms
- RFC 8058 Signaling One-Click Functionality for List Email Headers
- RFC 8066 IPv6 over Low-Power Wireless Personal Area Network ESC Dispatch Code Points and Guidelines