Authentication Indicator in Kerberos Tickets
RFC 8129, “Authentication Indicator in Kerberos Tickets”, is a Proposed Standard document published in March 2017 by A. Jain, N. Kinder, N. McCallum. It updates RFC 4120. The canonical text is published by the RFC Editor.
Abstract
This document updates RFC 4120, as it specifies an extension in the Kerberos protocol. It defines a new authorization data type, AD-AUTHENTICATION-INDICATOR. The purpose of introducing this data type is to include an indicator of the strength of a client's authentication in service tickets so that application services can use it as an input into policy decisions.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8129 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8128 IETF Appointment Procedures for the ICANN Root Zone Evolution Review Committee
- RFC 8130 RTP Payload Format for the Mixed Excitation Linear Prediction Enhanced Codec
- RFC 8127 Mobile Access Gateway Configuration Parameters Controlled by the Local Mobility Anchor
- RFC 8131 RSVP-TE Signaling Procedure for End-to-End GMPLS Restoration and Resource Sharing
- RFC 8126 Guidelines for Writing an IANA Considerations Section in RFCs
- RFC 8132 PATCH and FETCH Methods for the Constrained Application Protocol
- RFC 8125 Requirements for Password-Authenticated Key Agreement Schemes
- RFC 8133 The Security Evaluated Standardized Password-Authenticated Key Exchange Protocol