RFC 9588 · PROPOSED STANDARD · 2024

Kerberos Simple Password-Authenticated Key Exchange Pre- authentication

Overview

RFC 9588, “Kerberos Simple Password-Authenticated Key Exchange Pre- authentication”, is a Proposed Standard document published in August 2024 by N. McCallum, S. Sorce, R. Harwood, G. Hudson. The canonical text is published by the RFC Editor.

Abstract

This document defines a new pre-authentication mechanism for the Kerberos protocol. The mechanism uses a password-authenticated key exchange (PAKE) to prevent brute-force password attacks, and it may incorporate a second factor.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9588 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2024

Who Is Online

In total there are 53 users online: 0 registered, 47 guests and 6 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Facebook Majestic Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354