Network Working Group N. Williams Request for Comments: 5179 Sun Category: Standards Track May 2008Generic Security Service Application Program Interface (GSS-API) Domain-Based Service Names Mapping for the Kerberos V GSS Mechanism
Williams Standards Track [Page 1]
RFC 5179 Kerberos Domain-Based Names May 2008 1. Domain-Based Names for the Kerberos V GSS-API MechanismIn accordance with [RFC5178], this document provides the mechanism- specific details needed to implement GSS-API [RFC2743] domain-based service names with the Kerberos V GSS-API mechanism [RFC4121].
2. Conventions Used in This Document
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].
3. Internationalization Considerations
It is unclear, at this time, how best to address internationalization of Kerberos V domain-based principal names. This is because the Kerberos V core protocol internationalization project is incomplete.
Williams Standards Track [Page 2]
RFC 5179 Kerberos Domain-Based Names May 2008 4. Exampleso The domain-based name, of generic form, "ldap@foo.example@ds1.foo.example" may map to a Kerberos V principal name like: "ldap/ds1.foo.example/ foo.example@FOO.EXAMPLE"
5. Security Considerations
See [RFC5178].
6. Normative References
[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
Williams Standards Track [Page 3]
RFC 5179 Kerberos Domain-Based Names May 2008
Author's Address
Williams Standards Track [Page 4]
RFC 5179 Kerberos Domain-Based Names May 2008
Full Copyright Statement