Network Working Group Brian A. Anderson
Request for Comments: 927 BBN
December 1984
TACACS User Identification Telnet Option
1. Command name and code
TUID 26
2. Command Meanings
IAC WILL TUID
Anderson [Page 1]
RFC 927 December 1984
TUID Telnet Option
IAC DON'T TUID
3. Default
WON'T TUID
4. Motivation for the Option
Under TACACS (the TAC Access Control System) a user must be authenticated (give a correct name/password pair) to a TAC before he can connect to a host via the TAC. To avoid a second authentication by the target host, the TAC can pass along the user's proven identity (his UUID) to the that host. Hosts may accept the TAC's authentication of the user or not, at their option.
5. Description for the Option
At the time that a host establishes a TELNET connection for a user to another host, if the latter supports the TUID option and wants to receive the user's UUID, it sends an IAC DO TUID to the the user's host. If the user's host supports the TUID option and wants to authenticate the user by sending the user's UUID, it responds IAC WILL TUID; otherwise it responds with IAC WON'T TUID. If both the user and server TELNETs agree, the user TELNET will then send the UUID to the server TELNET by sub-negotiation.
Anderson [Page 2]
RFC 927 December 1984 TUID Telnet Option 6. ExamplesThere are two possible negotiations that result in the double login avoidance authentication of a user. Both the server and the user TELNET support the TUID option.
Anderson [Page 3]
RFC 927 December 1984
TUID Telnet Option
If the UUID had the value of all ones the following string of octets would be transmitted: