Internet Engineering Task Force (IETF) A. Jain
Request for Comments: 8129 Georgia Tech
Updates: 4120 N. Kinder
Category: Standards Track N. McCallum
ISSN: 2070-1721 Red Hat, Inc.
March 2017
Authentication Indicator in Kerberos Tickets
Jain, et al. Standards Track [Page 1]
RFC 8129 Authentication Indicator March 2017
Table of Contents
1. Introduction
Kerberos [RFC4120] allows secure interaction among users and services over a network. It supports a variety of authentication mechanisms using its pre-authentication framework [RFC6113]. The Kerberos authentication service has been architected to support password-based authentication as well as multi-factor authentication using one-time password devices, public-key cryptography, and other pre-authentication schemes. Implementations that offer pre-authentication mechanisms supporting significantly different strengths of client authentication may choose to keep track of the strength of the authentication that was used, for use as an input into policy decisions.
2. Document Conventions
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in RFC 2119 [RFC2119].
3. AD Type Specification
The Key Distribution Center (KDC) MAY include authorization data of ad-type 97, wrapped in AD-CAMMAC, in initial credentials. The KDC MAY copy it from a ticket-granting ticket into service tickets. The corresponding ad-data field contains the DER encoding [X.690] of the following ASN.1 [X.680] type:
Jain, et al. Standards Track [Page 2]
RFC 8129 Authentication Indicator March 2017
AD-AUTHENTICATION-INDICATOR ::= SEQUENCE OF UTF8String
4. Assigned Numbers
RFC 4120 [RFC4120] is updated in the following way:
5. Security Considerations
Elements of type AD-AUTHENTICATION-INDICATOR are wrapped in AD-CAMMAC containers. AD-CAMMAC supersedes AD-KDC-ISSUED and allows both application services and the KDC to verify the authenticity of the contained authorization data.
Jain, et al. Standards Track [Page 3]
RFC 8129 Authentication Indicator March 2017
Application service evaluation of site-defined indicators MUST consider the realm of original authentication in order to avoid cross-realm indicator collisions. Failure to enforce this property can result in invalid authorization decisions.
6. IANA Considerations
This document does not require any IANA actions.7. References 7.1. Normative References[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
Jain, et al. Standards Track [Page 4]
RFC 8129 Authentication Indicator March 2017
[X.690] ITU-T, "Information technology -- ASN.1 encoding rules:
7.2. Informative References
[RFC6711] Johansson, L., "An IANA Registry for Level of Assurance
Jain, et al. Standards Track [Page 5]
RFC 8129 Authentication Indicator March 2017 Appendix A. ASN.1 ModuleKerberosV5AuthenticationIndicators {