I-D Action:draft-zhu-negoex-01.txt

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



A New Internet-Draft is available from the on-line Internet-Drafts directories.

	Title           : The Extended GSS-API Negotiation Mechanism (NEGOEX)
	Author(s)       : L. Zhu, et al.
	Filename        : draft-zhu-negoex-01.txt
	Pages           : 22
	Date            : 2008-07-14

This document defines the Extended Generic Security Service
Application Program Interface (GSS-API) Negotiation Mechanism
(NegoEx).  NegoEx is a pseudo-security mechanism that logically
extends the SPNEGO protocol as defined in RFC4178.

The NegoEx protocol itself is a security mechanism negotiated by
SPNEGO.  When selected as the common mechanism, NegoEx OPTIONALLY
adds a pair of meta-data messages for each negotiated security
mechanism.  The meta-data exchange allows security mechanisms to
exchange auxiliary information such as trust configurations, thus
NegoEx provides additional flexibility than just exchanging object
identifiers in SPNEGO.

NegoEx preserves the optimistic token semantics of SPNEGO and applies
that recursively.  Consequently a context establishment mechanism
token can be included in the initial NegoEx message, and NegoEx does
not require an extra round-trip when the initiator's optimistic token
is accepted by the target.

Similar to SPNEGO, NegoEx defines a few new GSS-API extensions that a
security mechanism MUST support in order to be negotiated by NegoEx.
This document defines these GSS-API extensions.

Unlike SPNEGO however, NegoEx defines its own way for signing the
protocol messages in order to protect the protocol negotiation.  The
NegoEx message signing or verification can occur before the security
context for the negotiated real security mechanism is fully
established.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-zhu-negoex-01.txt

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.
<ftp://ftp.ietf.org/internet-drafts/draft-zhu-negoex-01.txt>
_______________________________________________

I-D-Announce@ietf.org
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt

[Index of Archives]     [IETF]     [IETF Discussion]     [Linux Kernel]

  Powered by Linux