Generic Security Service API Version 2: Java Bindings Update
RFC 8353, “Generic Security Service API Version 2: Java Bindings Update”, is a Proposed Standard document published in May 2018 by M. Upadhyay, S. Malkani, W. Wang. It obsoletes RFC 5653. The canonical text is published by the RFC Editor.
Abstract
The Generic Security Services Application Programming Interface (GSS-API) offers application programmers uniform access to security services atop a variety of underlying cryptographic mechanisms. This document updates the Java bindings for the GSS-API that are specified in "Generic Security Service API Version 2: Java Bindings Update" (RFC 5653). This document obsoletes RFC 5653 by adding a new output token field to the GSSException class so that when the initSecContext or acceptSecContext methods of the GSSContext class fail, it has a chance to emit an error token that can be sent to the peer for debugging or informational purpose. The stream-based GSSContext methods are also removed in this version.
The GSS-API is described at a language-independent conceptual level in "Generic Security Service Application Program Interface Version 2, Update 1" (RFC 2743). The GSS-API allows a caller application to authenticate a principal identity, to delegate rights to a peer, and to apply security services such as confidentiality and integrity on a per-message basis. Examples of security mechanisms defined for GSS-API are "The Simple Public-Key GSS-API Mechanism (SPKM)" (RFC 2025) and "The Kerberos Version 5 Generic Security Service Application Program Interface (GSS-API) Mechanism: Version 2" (RFC 4121).
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8353 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8352 Energy-Efficient Features of Internet of Things Protocols
- RFC 8354 Use Cases for IPv6 Source Packet Routing in Networking
- RFC 8351 The PKCS #8 EncryptedPrivateKeyInfo Media Type
- RFC 8355 Resiliency Use Cases in Source Packet Routing in Networking Networks
- RFC 8350 Alternate Tunnel Encapsulation for Data Frames in Control and Provisioning of Wireless Access Points
- RFC 8356 Experimental Codepoint Allocation for the Path Computation Element Communication Protocol
- RFC 8349 A YANG Data Model for Routing Management
- RFC 8357 Generalized UDP Source Port for DHCP Relay