{ "draft": "draft-ietf-krb-wg-preauth-framework-17", "doc_id": "RFC6113", "title": "A Generalized Framework for Kerberos Pre-Authentication", "authors": [ "S. Hartman", "L. Zhu" ], "format": [ "TEXT", "HTML" ], "page_count": "48", "pub_status": "PROPOSED STANDARD", "status": "PROPOSED STANDARD", "source": "Kerberos", "abstract": "Kerberos is a protocol for verifying the identity of principals (e.g., a workstation user or a network server) on an open network. The Kerberos protocol provides a facility called pre-authentication. Pre-authentication mechanisms can use this facility to extend the Kerberos protocol and prove the identity of a principal.\n\n This document describes a more formal model for this facility. The model describes what state in the Kerberos request a pre-authentication mechanism is likely to change. It also describes how multiple pre-authentication mechanisms used in the same request will interact.\n\n This document also provides common tools needed by multiple pre-authentication mechanisms. One of these tools is a secure channel between the client and the key distribution center with a reply key strengthening mechanism; this secure channel can be used to protect the authentication exchange and thus eliminate offline dictionary attacks. With these tools, it is relatively straightforward to chain multiple authentication mechanisms, utilize a different key management system, or support a new key agreement algorithm. [STANDARDS-TRACK]", "pub_date": "April 2011", "keywords": [], "obsoletes": [], "obsoleted_by": [], "updates": [ "RFC4120" ], "updated_by": [], "see_also": [], "doi": "10.17487/RFC6113", "errata_url": null }