Public Key Cryptography for Initial Authentication in Kerberos Algorithm Agility
RFC 8636, “Public Key Cryptography for Initial Authentication in Kerberos Algorithm Agility”, is a Proposed Standard document published in July 2019 by L. Hornquist Astrand, L. Zhu, M. Cullen, G. Hudson. It updates RFC 4556. The canonical text is published by the RFC Editor.
Abstract
This document updates the Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) standard (RFC 4556) to remove protocol structures tied to specific cryptographic algorithms. The PKINIT key derivation function is made negotiable, and the digest algorithms for signing the pre-authentication data and the client's X.509 certificates are made discoverable.
These changes provide preemptive protection against vulnerabilities discovered in the future in any specific cryptographic algorithm and allow incremental deployment of newer algorithms.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8636 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8635 Router Keying for BGPsec
- RFC 8637 Applicability of the Path Computation Element to the Abstraction and Control of TE Networks
- RFC 8634 BGPsec Router Certificate Rollover
- RFC 8638 IPv4 Multicast over an IPv6 Multicast in Softwire Mesh Networks
- RFC 8633 Network Time Protocol Best Current Practices
- RFC 8639 Subscription to YANG Notifications
- RFC 8632 A YANG Data Model for Alarm Management
- RFC 8640 Dynamic Subscription to YANG Events and Datastores over NETCONF