Authentication Indicator in Kerberos Tickets (RFC8129) Disclosure Number: IPCOM000249706D
Original Publication Date: 2017-Mar-01
Included in the Prior Art Database: 2017-Mar-23
Document File: 12 page(s) / 11K

Kerberos [RFC4120] allows secure interaction among users and services over a network. It supports a variety of authentication mechanisms using its pre-authentication framework [RFC6113]. The Kerberos authentication service has been architected to support password-based authentication as well as multi-factor authentication using one-time password devices, public-key cryptography, and other pre-authentication schemes. Implementations that offer pre-authentication mechanisms supporting significantly different strengths of client authentication may choose to keep track of the strength of the authentication that was used, for use as an input into policy decisions.

Internet Engineering Task Force (IETF)                           A. Jain Request for Comments: 8129                                  Georgia Tech Updates: 4120                                                  N. Kinder Category: Standards Track                                    N. McCallum ISSN: 2070-1721                                            Red Hat, Inc.                                                               March 2017

               Authentication Indicator in Kerberos Tickets


   This document updates RFC 4120, as it specifies an extension in the    Kerberos protocol.  It defines a new authorization data type,    AD-AUTHENTICATION-INDICATOR.  The purpose of introducing this data    type is to include an indicator of the strength of a client's    authentication in service tickets so that application services can    use it as an input into policy decisions.

