(Logo Tech-invite)  

a Portal devoted to SIP and Security technologies

  (World Map)    
    Search Home Site Map Contact
 SIP/IMS Standardization
> IETF Standardization Process
> RFCs related to SIP (4 p.) o
> SIP-SIPPING-SIMPLE... I-Ds (22 p.) o
> Audio-Video Transport RFCs (2 p.)
> 3GPP Specifications (12 p.)
> OMA Specifications related to SIP
> TISPAN NGN Specifications (3 p.) o
> SIP Topics
> IMS Topics
 SIP/IMS Call Flows
> RFC3261's Example
> Basic -- RFC3665
> SIP PSTN -- RFC3666 (3 p.)
> SIP Service Examples (19 p.)
> IMS Signaling Flows (35 p.)
 SIP/IMS Architecture
> SIP Protocol Structure
> Dialogs & Routing
> UMTS Network Evolution
 Security
> PKIX-TLS-SMIME... Standards (20 p.) o
> Cryptography Basics
> ASN.1 for PKI Certificate & CRL Profile
> ASN.1 for CMS
> RFC3280's Certificate Examples (4)
> RFC4134's CMS-S/MIME Examples (14)
> RFC4474's SIP Authentication Service
> SSL/TLS Time-Diagrams
> IPSec Guides
 ABNF Grammars
> ABNF Notation & Rules
> URI Generic Syntax
> ABNF for SIP
> SIP Messages & URIs
> SIP Header Fields
> MIME Media Types
> ABNF for SDP
> ABNF for MSRP
> ABNF for MRCPv2
> ABNF for RTSP 2.0
> Internet Message Format
 DiffServ CoS Simulation
> IPVCoSS Simulator
> IP-VPN Case Study
  o (daily updated)
> I-D Tracker States   Security (SEC) area
  > PKIXwg   > TLSwg   > SMIMEwg   > [IPSECwg]   > [SECSHwg]   > BTNSwg   > DKIMwg
  > EMUwg   > HOKEYwg   > ISMSwg   > KEYPROVwg   > KITTENwg   > KRBwg   > LTANSwg
  > MSECwg   > NEAwg   > SASLwg   > SYSLOGwg   > Miscellaneous    
> RAI Area's WGs > SEC Area's WGs > Miscellaneous WGs  

Chairs:

Jeffrey Hutzelman
Larry Zhu
 

Useful Links:

tools.ietf.org/wg/krb-wg
KRB-WG mail-archive

 

RFCs & Drafts related to
KRB-WG working group


Chicago IETF-69 minutes
Vancouver IETF-70 minutes
Philadelphia IETF-71 minutes
WG-KRB
Security (SEC) area
Top I-D List RFC List Charter Published RFCs
  IDs in RFC Ed Queue IDs Processed by IESG IETF: ID Exists Individual: ID Exists
## PKIXwg ## TLSwg ## SMIMEwg ## IPSECwg ## SECSHwg ## BTNSwg ## DKIMwg ## EMUwg ## HOKEYwg ## ISMSwg
## KEYPROVwg ## KITTENwg ## KRBwg ## LTANSwg ## MSECwg ## NEAwg ## SASLwg ## SYSLOGwg ## Miscellaneous

List of Drafts

KRB working group

Last Update: May 05, 2008 -- Color Legend: RFC Editor Queue / Processed by IESG / ID Exists / Recently Expired -- Each I-D name is a link to an I-D description, which points to a text version, a two-page and fit-in-window PDF version, as well as the IETF Tools' HTML version.
 
# ietf-krb-wg-anon
# ietf-krb-wg-cross-problem-statement
# ietf-krb-wg-gss-cb-hash-agility
# ietf-krb-wg-iakerb
# ietf-krb-wg-kdc-model
# ietf-krb-wg-kerberos-referrals
# ietf-krb-wg-kerberos-set-passwd
# ietf-krb-wg-naming
# ietf-krb-wg-otp-preauth
# ietf-krb-wg-preauth-framework
# kamada-krb-client-friendly-cross
# rabinovich-krb-wg-x509-name-constraints
# zhu-pkinit-ecc
 
Security (SEC) area
Top I-D List RFC List Charter Published RFCs
  IDs in RFC Ed Queue IDs Processed by IESG IETF: ID Exists Individual: ID Exists
## PKIXwg ## TLSwg ## SMIMEwg ## IPSECwg ## SECSHwg ## BTNSwg ## DKIMwg ## EMUwg ## HOKEYwg ## ISMSwg
## KEYPROVwg ## KITTENwg ## KRBwg ## LTANSwg ## MSECwg ## NEAwg ## SASLwg ## SYSLOGwg ## Miscellaneous

List of RFCs

KRB working group

 
RFC 3961 (ietf-krb-wg-crypto)
RFC 3962 (raeburn-krb-rijndael-krb)
RFC 4120 (ietf-krb-wg-kerberos-clarifications)
RFC 4121 (ietf-krb-wg-gssapi-cfx)
RFC 4537 (zhu-kerb-enctype-nego)
RFC 4556 (ietf-cat-kerberos-pk-init)
RFC 4557 (ietf-krb-wg-ocsp-for-pkinit)
RFC 5021 (ietf-krb-wg-tcp-expansion)
 
Security (SEC) area
Top I-D List RFC List Charter Published RFCs
  IDs in RFC Ed Queue IDs Processed by IESG IETF: ID Exists Individual: ID Exists
## PKIXwg ## TLSwg ## SMIMEwg ## IPSECwg ## SECSHwg ## BTNSwg ## DKIMwg ## EMUwg ## HOKEYwg ## ISMSwg
## KEYPROVwg ## KITTENwg ## KRBwg ## LTANSwg ## MSECwg ## NEAwg ## SASLwg ## SYSLOGwg

Charter

KRB working group

The charter of the KRB-WG working group is reported below.
Kerberos over the years has been ported to virtually every operating system. There are at least two open source versions, with numerous commercial versions based on these and other proprietary implementations. Kerberos evolution has continued in recent years, with the development of a new crypto framework, publication of a new version of the Kerberos specification, support for initial authentication using public keys, and numerous extensions developed in and out of the IETF.

However, wider deployment and advances in technology bring with them both new challenges and new opportunities, particularly with regard to making initial authentication of users to the Kerberos system both convenient and secure. In addition, several key features remain undefined.

The Kerberos Working Group will continue to improve the core Kerberos specification, develop extensions to address new needs and technologies related to improving the process of client authentication, and produce specifications for missing functionality.

Specifically, the Working Group will:

o Complete existing work:

- ECC for PKINIT (draft-zhu-pkinit-ecc-03.txt)

- Set/Change Password (draft-ietf-krb-wg-kerberos-set-passwd-05.txt)

- Naming Constraints (draft-ietf-krb-wg-naming-02.txt)

- Anonymity (draft-ietf-krb-wg-anon-03.txt)

- Hash agility for GSS-KRB5 (draft-ietf-krb-wg-gss-cb-hash-agility-00.txt)

- Hash agility for PKINIT (draft-ietf-krb-wg-pkinit-alg-agility-01.txt)

- Referrals (draft-ietf-krb-wg-kerberos-referrals-08.txt)

o Prepare and advance a specification for an updated, backward- compatible version of the Kerberos version 5 protocol which supports non-ASCII principal and realm names, salt strings, and passwords; insures that those portions of the protocol which are not encrypted are nonetheless authenticated whenever possible; and enables future protocol revisions and extensions.

o Develop extensions which reduce or eliminate exposure of Kerberos clients' long-term keys to attack and enable the use of alternate mechanisms for initial authentication. This task will comprise the following items:

- A model and framework for preauthentication mechanisms

- A mechanism for providing a protected channel for carrying preauthentication data and/or a reply key between a Kerberos client and KDC, within the KDC_REQ/KDC_REP exchange.

- Support for One-Time Passwords

- Support for hardware authentication tokens

- Support for using TLS to secure communications with Kerberos KDCs.

o Examine issues related to the current cross-realm model, produce a list of problems to be solved, and evaluate approaches to solving them.

o Develop extensions to Kerberos and a GSS-API mechanism (IAKERB) to enable Kerberos clients to communicate with a KDC by using a GSS-API acceptor as a proxy.

o Produce a data model for information needed by the KDC, and an LDAP schema for management of that data.
Security (SEC) area
Top I-D List RFC List Charter Published RFCs
  IDs in RFC Ed Queue IDs Processed by IESG IETF: ID Exists Individual: ID Exists
## PKIXwg ## TLSwg ## SMIMEwg ## IPSECwg ## SECSHwg ## BTNSwg ## DKIMwg ## EMUwg ## HOKEYwg ## ISMSwg
## KEYPROVwg ## KITTENwg ## KRBwg ## LTANSwg ## MSECwg ## NEAwg ## SASLwg ## SYSLOGwg ## Miscellaneous

Published RFCs

KRB working group

RFC3961
02/2005
(50 p.)
[html]
[pdf(2)]
K. Raeburn
Encryption and Checksum Specifications
This document describes a framework for defining encryption and checksum mechanisms for use with the Kerberos protocol, defining an abstraction layer between the Kerberos protocol and related protocols, and the actual mechanisms themselves. The document also defines several mechanisms. Some are taken from RFC 1510, modified in form to fit this new framework and occasionally modified in content when the old specification was incorrect. New mechanisms are presented here as well. This document does NOT indicate which mechanisms may be considered "required to implement".
Up  List Status:Proposed Standard  
RFC3962
02/2005
(16 p.)
[html]
[pdf(2)]
K. Raeburn
Advanced Encryption Standard (AES) Encryption for Kerberos 5
The United States National Institute of Standards and Technology (NIST) has chosen a new Advanced Encryption Standard (AES), which is significantly faster and (it is believed) more secure than the old Data Encryption Standard (DES) algorithm. This document is a specification for the addition of this algorithm to the Kerberos cryptosystem suite.
Up  List Status:Proposed Standard  
RFC4120
07/2005
(138 p.)
[html]
[pdf(2)]
C. Neuman
T. Yu
S. Hartman
K. Raeburn
The Kerberos Network Authentication Service (V5)
This document provides an overview and specification of Version 5 of the Kerberos protocol, and it obsoletes RFC 1510 to clarify aspects of the protocol and its intended use that require more detailed or clearer explanation than was provided in RFC 1510. This document is intended to provide a detailed description of the protocol, suitable for implementation, together with descriptions of the appropriate use of protocol messages and fields within those messages.
Up  List Status:Proposed Standard -- Updated by: RFC4537, RFC5021
RFC4121
07/2005
(20 p.)
[html]
[pdf(2)]
L. Zhu
K. Jaganathan
S. Hartman
The Kerberos Version 5 Generic Security Service Application Program Interface (GSS-API) Mechanism: Version 2
This document defines protocols, procedures, and conventions to be employed by peers implementing the Generic Security Service Application Program Interface (GSS-API) when using the Kerberos Version 5 mechanism.

RFC 1964 is updated and incremental changes are proposed in response to recent developments such as the introduction of Kerberos cryptosystem framework. These changes support the inclusion of new cryptosystems, by defining new per-message tokens along with their encryption and checksum algorithms based on the cryptosystem profiles.
Up  List Status:Proposed Standard  
RFC4537
06/2006
(6 p.)
[html]
[pdf(2)]
L. Zhu
P. Leach
K. Jaganathan
Kerberos Cryptosystem Negotiation Extension
This document specifies an extension to the Kerberos protocol as defined in RFC 4120, in which the client can send a list of supported encryption types in decreasing preference order, and the server then selects an encryption type that is supported by both the client and the server.
Up  List Status:Proposed Standard -- Updates: RFC4120
RFC4556
06/2006
(42 p.)
[html]
[pdf(2)]
L. Zhu
B. Tung
Public Key Cryptography for Initial Authentication in Kerberos (PKINIT)
This document describes protocol extensions (hereafter called PKINIT) to the Kerberos protocol specification. These extensions provide a method for integrating public key cryptography into the initial authentication exchange, by using asymmetric-key signature and/or encryption algorithms in pre-authentication data fields.
Up  List Status:Proposed Standard -- Updates: RFC4120
RFC4557
06/2006
(6 p.)
[html]
[pdf(2)]
L. Zhu
K. Jaganathan
N. Williams
Online Certificate Status Protocol (OCSP) Support for Public Key Cryptography for Initial Authentication in Kerberos (PKINIT)
This document defines a mechanism to enable in-band transmission of Online Certificate Status Protocol (OCSP) responses in the Kerberos network authentication protocol. These responses are used to verify the validity of the certificates used in Public Key Cryptography for Initial Authentication in Kerberos (PKINIT), which is the Kerberos Version 5 extension that provides for the use of public key cryptography.
Up  List Status:Proposed Standard -- Updates: RFC4120
RFC5021
08/2007
(7 p.)
[html]
[pdf(2)]
S. Josefsson
Extended Kerberos Version 5 Key Distribution Center (KDC) Exchanges over TCP
This document describes an extensibility mechanism for the Kerberos V5 protocol when used over TCP transports. The mechanism uses the reserved high-bit in the length field. It can be used to negotiate TCP-specific Kerberos extensions.
Up  List Status:Proposed Standard -- Updates: RFC4120
Security (SEC) area
Top I-D List RFC List Charter Published RFCs
  IDs in RFC Ed Queue IDs Processed by IESG IETF: ID Exists Individual: ID Exists
## PKIXwg ## TLSwg ## SMIMEwg ## IPSECwg ## SECSHwg ## BTNSwg ## DKIMwg ## EMUwg ## HOKEYwg ## ISMSwg
## KEYPROVwg ## KITTENwg ## KRBwg ## LTANSwg ## MSECwg ## NEAwg ## SASLwg ## SYSLOGwg ## Miscellaneous

Drafts in the RFC Editor Queue

KRB working group

-
Security (SEC) area
Top I-D List RFC List Charter Published RFCs
  IDs in RFC Ed Queue IDs Processed by IESG IETF: ID Exists Individual: ID Exists
## PKIXwg ## TLSwg ## SMIMEwg ## IPSECwg ## SECSHwg ## BTNSwg ## DKIMwg ## EMUwg ## HOKEYwg ## ISMSwg
## KEYPROVwg ## KITTENwg ## KRBwg ## LTANSwg ## MSECwg ## NEAwg ## SASLwg ## SYSLOGwg ## Miscellaneous

Drafts currently processed by the IESG

KRB working group

krb-wg-anon-05
Waiting for
AD Go-Ahead

Jan 27, 2008
(11 p.)
[pdf(2)] [html]
L. Zhu
P. Leach
Anonymity Support for Kerberos
This document defines extensions to the Kerberos protocol for the Kerberos client to authenticate the Kerberos Key Distribution Center and the Kerberos server, without revealing the client's identity. It updates RFC 4120. These extensions can be used to secure communication between the anonymous client and the server.
Up  List Intended Status:Proposed Standard
krb-wg-naming-04
Waiting for
AD Go-Ahead

Oct 24, 2007
(7 p.)
[pdf(2)] [html]
L. Zhu
Additional Kerberos Naming Constraints
This document defines new naming constraints for well-known Kerberos principal name and well-known Kerberos realm names.
Up  List Intended Status:Proposed Standard
zhu-pkinit-ecc-04
Waiting for
AD Go-Ahead

Oct 24, 2007
(11 p.)
[pdf(2)] [html]
L. Zhu
K. Jaganathan
K. Lauter
ECC Support for PKINIT
This document describes the use of Elliptic Curve certificates, Elliptic Curve signature schemes and Elliptic Curve Diffie-Hellman (ECDH) key agreement within the framework of PKINIT - the Kerberos Version 5 extension that provides for the use of public key cryptography.
Up  List Intended Status:Informational
Security (SEC) area
Top I-D List RFC List Charter Published RFCs
  IDs in RFC Ed Queue IDs Processed by IESG IETF: ID Exists Individual: ID Exists
## PKIXwg ## TLSwg ## SMIMEwg ## IPSECwg ## SECSHwg ## BTNSwg ## DKIMwg ## EMUwg ## HOKEYwg ## ISMSwg
## KEYPROVwg ## KITTENwg ## KRBwg ## LTANSwg ## MSECwg ## NEAwg ## SASLwg ## SYSLOGwg ## Miscellaneous

Active IETF Drafts

KRB working group

krb-wg-cross-
problem-
statement-02

ID Exists
Dec 17, 2007
(13 p.)
[pdf(2)] [html]
S. Sakane
K. Kamada
S. Zrelli
M. Ishiyama
Problem statement on the cross-realm operation of Kerberos
There are some issues when the cross-realm operation of the Kerberos Version 5 [RFC 4120] is employed into actual specific systems. This document describes some examples of actual systems, and lists requirements and restriction of the operation in such system. Then it describes issues when we apply the cross-realm operation to such system.
Up  List Intended Status:Informational
krb-wg-gss-cb-
hash-agility-03

ID Exists
Nov 9, 2007
(12 p.)
[pdf(2)] [html]
S. Emery
Kerberos Version 5 GSS-API Channel Binding Hash Agility
Currently, the Kerberos Version 5 Generic Security Services Application Programming Interface (GSS-API) mechanism [RFC4121] does not have the ability to utilize better hash algorithms used to generate channel binding identities. The current mechanism for doing this is hard coded to use MD5 only. The purpose of this document is to outline changes required to update the protocol so that more secure algorithms can be used to create channel binding identities. The extensibility of this solution also provides an eventual replacement of identities based solely on hash algorithms.
Up  List Intended Status:Standards Track
krb-wg-iakerb-00
ID Exists
(Recently Expired)

Oct 31, 2007
(10 p.)
[pdf(2)] [html]
L. Zhu
J. Altman
Initial and Pass Through Authentication Using Kerberos V5 and the GSS-API (IAKERB)
This document defines extensions to the Kerberos protocol and the GSS-API Kerberos mechanism that enable a GSS-API Kerberos client to exchange messages with the KDC using the GSS-API acceptor as the proxy, by encapsulating the Kerberos messages inside GSS-API tokens. With these extensions a client can obtain Kerberos tickets for services where the KDC is not accessible to the client, but is accessible to the application server.
Up  List Intended Status:Standards Track
krb-wg-kdc-
model-01

ID Exists
Feb 6, 2008
(18 p.)
[pdf(2)] [html]
L. Johansson
An information model for Kerberos version 5
This document describes an information model for Kerberos version 5 from the point of view of an administrative service. There is no standard for administrating a kerberos 5 KDC. This document describes the services exposed by an administrative interface to a KDC.
Up  List Intended Status:Standards Track
krb-wg-kerberos-
referrals-10

ID Exists
Feb 25, 2008
(18 p.)
[pdf(2)] [html]
K. Raeburn
L. Zhu
Generating KDC Referrals to Locate Kerberos Realms
The memo documents a method for a Kerberos Key Distribution Center (KDC) to respond to client requests for Kerberos tickets when the client does not have detailed configuration information on the realms of users or services. The KDC will handle requests for principals in other realms by returning either a referral error or a cross-realm TGT to another realm on the referral path. The clients will use this referral information to reach the realm of the target principal and then receive the ticket.
Up  List Intended Status:Standards Track
krb-wg-kerberos-
set-passwd-07

ID Exists
(Recently Expired)

Sep 25, 2007
(41 p.)
[pdf(2)] [html]
N. Williams
Kerberos Set/Change Key/Password Protocol Version 2
This document specifies an extensible protocol for setting keys and changing the passwords of Kerberos V principals.
Up  List Intended Status:Standards Track
krb-wg-otp-
preauth-04

ID Exists
Apr 30, 2008
(33 p.)
[pdf(2)] [html]
G. Richards
OTP Pre-authentication
The Kerberos protocol provides a framework authenticating a client using the exchange of pre-authentication data. This document describes the use of this framework to carry out One Time Password (OTP) authentication.
Up  List Intended Status:Standards Track
krb-wg-preauth-
framework-07

ID Exists
Feb 24, 2008
(40 p.)
[pdf(2)] [html]
L. Zhu
S. Hartman
A Generalized Framework for Kerberos Pre-Authentication
Kerberos is a protocol for verifying the identity of principals (e.g., a workstation user or a network server) on an open network. The Kerberos protocol provides a mechanism called pre-authentication for proving the identity of a principal and for better protecting the long-term secret of the principal.

This document describes a model for Kerberos pre-authentication mechanisms. The model describes what state in the Kerberos request a pre-authentication mechanism is likely to change. It also describes how multiple pre-authentication mechanisms used in the same request will interact.

This document also provides common tools needed by multiple pre-authentication mechanisms. One of these tools is a secure channel between the client and the KDC with a reply key delivery mechanism; this secure channel can be used to protect the authentication exchange thus eliminate offline dictionary attacks. With these tools, it is relatively straightforward to chain multiple authentication mechanisms, utilize a different key management system, or support a new key agreement algorithm.
Up  List Intended Status:Standards Track
Security (SEC) area
Top I-D List RFC List Charter Published RFCs
  IDs in RFC Ed Queue IDs Processed by IESG IETF: ID Exists Individual: ID Exists
## PKIXwg ## TLSwg ## SMIMEwg ## IPSECwg ## SECSHwg ## BTNSwg ## DKIMwg ## EMUwg ## HOKEYwg ## ISMSwg
## KEYPROVwg ## KITTENwg ## KRBwg ## LTANSwg ## MSECwg ## NEAwg ## SASLwg ## SYSLOGwg ## Miscellaneous

Active Individual Drafts

KRB working group

kamada-krb-
client-friendly-
cross-03

ID Exists
Nov 16, 2007
(14 p.)
[pdf(2)] [html]
K. Kamada
S. Sakane
Client-Friendly Cross-Realm Model for Kerberos 5
This document proposes a cross-realm traversal model, which is suitable for resource-limited clients, for Kerberos Version 5. This model relieves the clients of the traversal cost by two means. One moves the cost of consecutive Ticket-Granting Service (TGS) exchanges from clients to Key Distribution Centers (KDCs). The other reduces the traversal cost itself by generating a direct inter-realm relationship between two realms. The document describes behavior of clients and KDCs, but does not specify any wire format, which need to be specified separately.
Up  List Intended Status:-
rabinovich-krb-wg-
x509-name-
constraints-00

ID Exists
(Recently Expired)

Sep 11, 2007
(18 p.)
[pdf(2)] [html]
P. Rabinovich
Constraining Kerberos Names in X.509 Certificates
This document specifies mechanisms for constraining Kerberos names in X.509 certificates. These mechanisms are defined within the name constraints framework standardized in RFC 3280 and apply to Kerberos names in X.509 certificates compliant with RFC 4556.
Up  List Intended Status:-
  
Last update: May 05, 2008 
  
(to top) © 2005-2008 Joël Repiquet, All Rights Reserved.