Click here for our home page Click here to find out about us Click here for products & services Click here for support Click here for news Click here for details of our partners Click here for our contact details
CyberSafe logo
News • Standards
Click here for Kerberos news
Click here for general information
Click here for tutorials
Click here for recommended books
Click here for standards
Click here for the Press pages
Click here for the Newsletter
Click here for Events
Click here for application vendors
Click here for CyberSafe and Microsoft news

IETF Standards

 

IETF Drafts associated with the Kerberos protocol

Internet-Drafts ("ID's") are working documents of the Internet Engineering Task Force (IETF), its areas, and its working groups. When a draft is revised it replaces all previous versions of the draft and they are removed from the draft directory. Un revised documents placed in the Internet-Drafts directories have a maximum life of six months, after which time they must be updated, or they will be deleted. After an Internet-Draft document becomes an RFC, it will be replaced in the Internet-Drafts Directories with an announcement to that effect.

 

A list of the ID's being progressed by the Kerberos WG can be found here and summarised below :

 

Public Key Cryptography for Initial Authentication in Kerberos
 

Initial and Pass Through Authentication Using Kerberos V5 and GSS-API (IAKERB)

Distributing Kerberos KDC and Realm Information with DNS

Kerberos Set/Change Password: Version 2

 

Kerberos KDC LDAP Schema

 

Passwordless Initial Authentication to Kerberos by Hardware Preauthentication

 

Encryption and Checksum Specifications for Kerberos 5

 

The Kerberos Network Authentication Service (V5) - Also known as Kerberos Clarifications

 

Preparation of Internationalised Strings Profile for Kerberos UTF-8 Strings

 

Keys Extension for the Kerberos KDC LDAP Schema

 

Integrating Single-use Authentication Mechanisms with Kerberos

 

= Currently implemented in CyberSafe products

 

Other ID's that are related to Kerberos, but not currently being progressed. They either need fixing, and/or need renewed interest to progress.

 

 

Kerberised Internet Negotiation of Keys (KINK)

 

Requirements for Kerberised Internet Negotiation of Keys

 

Public Key Cryptography for Cross-Realm Authentication in Kerberos

 

Extensible Authentication Protocol (EAP) GSS Authentication Protocol

 

The Windows 2000 RC4-HMAC Kerberos encryption type

 

Kerberos Cipher Suites in Transport Layer Security (TLS)

 

Rijndael, Serpent, and Twofish Cryptosystems for Kerberos 5

 

HTTP Authentication: SPNEGO Access Authentication

 

Kerberos KDC LDAP Schema

 

  User to User Kerberos Authentication using GSS-API
  Generating KDC Referrals to locate Kerberos realms
  A Kerberos Security Model for SNMPv3
  DHCP Authentication Via Kerberos V
  The Lightweight Kerberos Protocol
  Radius Security Extensions using Kerberos v5
  Informational: Kerberos GeneralString to be Interpreted as ASCII Only
   
= Currently implemented in CyberSafe products

 

IETF RFC's associated with the Kerberos protocol

  RFC1411 Telnet Authentication: Kerberos Version 4 (Experimental)
RFC1510 The Kerberos Network Authentication Service (V5) (Proposed Standard)
RFC1964 The Kerberos Version 5 GSS-API Mechanism (Proposed Standard)
  RFC2478 The Simple and Protected GSS-API Negotiation Mechanism (Proposed Standard)
  RFC2623 NFS Version 2 and Version 3 Security Issues and the NFS Protocol's Use of RPCSEC_GSS and Kerberos V5 (Proposed Standard)
  RFC2712 Addition of Kerberos Cipher Suites to Transport Layer Security (TLS) (Proposed Standard)
RFC2743 Generic Security Service Application Program Interface (GSS-API) Version 2, Update 1 (Proposed Standard)
RFC2744 Generic Security Service API (GSS-API) Version 2 : C-bindings (Proposed Standard)
RFC2853 Generic Security Service API (GSS-API) Version 2 : Java Bindings (Proposed Standard)
RFC2942 Telnet Authentication: Kerberos Version 5 (Proposed Standard)
  RFC3129 Requirements for Kerberised Internet Negotiation of Keys. (Informational)
RFC3244 Microsoft Windows 2000 Kerberos Change Password and Set Password Protocols
   
= Currently implemented in CyberSafe products

 

CableLabs Standards

 

Security standards associated with the Kerberos protocol

Founded in 1988 by members of the cable television industry, Cable Television Laboratories, Inc. (CableLabs®) is a nonprofit research and development consortium that is dedicated to pursuing new cable telecommunications technologies and to helping its cable operator members integrate those technical advancements into their business objectives. PacketCable is a CableLabs-led initiative aimed at developing interoperable interface specifications for delivering advanced, real-time multimedia services over two-way cable plant. Built on top of the industry's highly successful cable modem infrastructure, PacketCable networks will use Internet protocol (IP) technology to enable a wide range of multimedia services, such as IP telephony, multimedia conferencing, interactive gaming, and general multimedia applications. Working with CableLabs member companies and technology suppliers, the PacketCable project will address issues such as device interoperability and product compliance with the PacketCable specifications.

 

You will need Adobe Acrobat Reader to view these files.

 

PacketCable Security Specification
   
= Partially implemented in CyberSafe products