Kerberos Authorization Data Container Authenticated by Multiple Message Authentication Codes (MACs)
Author(s) -
Salvatore Sorce,
Tom Yu
Publication year - 2016
Publication title -
rfc
Language(s) - English
Resource type - Reports
DOI - 10.17487/rfc7751
Subject(s) - kerberos , computer science , authentication (law) , authorization , container (type theory) , message authentication code , computer security , computer network , cryptography , engineering , mechanical engineering
This document specifies a Kerberos authorization data container thatsupersedes AD-KDC-ISSUED. It allows for multiple MessageAuthentication Codes (MACs) or signatures to authenticate thecontained authorization data elements. The multiple MACs are needed tomitigate shortcomings in the existing AD-KDC-ISSUED container. Thisdocument updates RFC 4120.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom