IETF RFC 5896 PDF

IETF RFC 5896 PDF

Name:
IETF RFC 5896 PDF

Published Date:
06/01/2010

Status:
[ Active ]

Description:

Generic Security Service Application Program Interface (GSS-API): Delegate if Approved by Policy

Publisher:
Internet Engineering Task Force

Document status:
Active

Format:
Electronic (PDF)

Delivery time:
10 minutes

Delivery time (for Russian version):
200 business days

SKU:

Choose Document Language:
$9.3
Need Help?

Introduction

Several GSS-API applications work in a multi-tiered architecture, where the server takes advantage of delegated user credentials to act on behalf of the user and contact additional servers. In effect, the server acts as an agent on behalf of the user. Examples include web applications that need to access e-mail or file servers, including CIFS file servers. However, delegating user credentials to a party who is not sufficiently trusted is problematic from a security standpoint.

Today, GSS-API [RFC2743] leaves the determination of whether delegation is desired to the client application. An application requests delegation by setting the deleg_req_flag when calling init_sec_context. This requires client applications to know what services should be trusted for delegation.

However, blindly delegating to services for applications that do not need delegation is problematic. In some cases, a central authority is in a better position than the client application to know what services should receive delegation. Some GSS-API mechanisms have a facility to allow an administrator to communicate that a particular service is an appropriate target for delegation. For example, a Kerberos [RFC4121] KDC can set the OK-AS-DELEGATE flag in issued tickets as such an indication. It is desirable to expose this knowledge to the GSS-API client so the client can request delegation if and only if central policy recommends delegation to the given service.

This specification adds a new input flag to gss_init_sec_context() to request delegation when approved by central policy. In addition, a constant value to be used in the GSS-API C bindings [RFC2744] is defined. Finally, the behavior for the Kerberos mechanism [RFC4121] is specified.


Edition : 10
File Size : 1 file , 11 KB
Number of Pages : 6
Published : 06/01/2010

History


Related products

IETF RFC 2213
Published Date: 09/01/1997
Integrated Services Management Information Base using SMIv2
$11.1

Best-Selling Products

A4A A4A PUBLICATIONS LIBRARY
Published Date: 01/01/2016
A4A Publications Library...Includes various e-business, operations and safety publications
A4A A4A PUBLICATIONS LIBRARY
Published Date: 01/01/2017
A4A Publications Library...Includes various e-business, operations and safety publications
A4A A4A PUBLICATIONS LIBRARY
Published Date: 01/01/2020
A4A Publications Library
$3429
A4A A4A PUBLICATIONS LIBRARY
Published Date: 01/01/2019
A4A Publications Library
A4A CSDD
Published Date: 01/01/2020
Common Support Data Dictionary (CSDD)
$191.4
A4A CSDD
Published Date: 01/01/2017
Common Support Data Dictionary (CSDD)