I-D Action: draft-ietf-kitten-channel-bound-flag-00.txt

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.

	Title           : Channel Binding Signalling for the Generic Security Services Application Programming Interface
	Author(s)       : Nicolas Williams
	Filename        : draft-ietf-kitten-channel-bound-flag-00.txt
	Pages           : 13
	Date            : 2013-07-07

Abstract:
   Channel binding is a technique that allows applications to use a
   secure channel at a lower layer without having to use authentication
   at that lower layer.  The concept of channel binding comes from the
   Generic Security Services Application Programming Interface (GSS-
   API).  It turns out that the semantics commonly implemented are
   different that those specified in the base GSS-API RFC (RFC2743), and
   that that specification has a serious bug.  This document addresses
   both, the inconsistency as-implemented and the specification bug.

   This Internet-Draft proposes the addition of a "channel bound" return
   flag for the GSS_Init_sec_context() and GSS_Accept_sec_context()
   functions.  Two behaviors are specified: a default, safe behavior
   reflecting existing implementation deployments, and a behavior that
   is only safe when the application specifically tells the GSS-API that
   it (the application) supports the new behavior.  Additional API
   elements related to this are also added, including a new security
   context establishment API.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-kitten-channel-bound-flag

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-kitten-channel-bound-flag-00


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
I-D-Announce mailing list
I-D-Announce@ietf.org
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt



[Index of Archives]     [IETF]     [IETF Discussion]     [Linux Kernel]

  Powered by Linux