GSS-API

GSS-API (Generic Security Service Application Program Interface) and its mechanisms

GSS-API subjects:

GSS-API RFCs (65)

Display RFCs as
  • RFC 9588: Kerberos Simple Password-Authenticated Key Exchange (SPAKE) Pre-authentication

    Proposed Standard
  • RFC 9266: Channel Bindings for TLS 1.3

    Proposed Standard
  • RFC 8732: Generic Security Service Application Program Interface (GSS-API) Key Exchange with SHA-2

    Proposed Standard
  • RFC 8636: Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) Algorithm Agility

    Proposed Standard
  • RFC 8429: BCP 218: Deprecate Triple-DES (3DES) and RC4 in Kerberos

    Best Current Practice
  • RFC 8353: Generic Security Service API Version 2: Java Bindings Update

    Proposed Standard
  • RFC 8129: Authentication Indicator in Kerberos Tickets

    Proposed Standard
  • RFC 8062: Anonymity Support for Kerberos

    Proposed Standard
  • RFC 8070: Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) Freshness Extension

    Proposed Standard
  • RFC 7861: Remote Procedure Call (RPC) Security Version 3

    Proposed Standard
  • RFC 8009: AES Encryption with HMAC-SHA2 for Kerberos 5

    Informational
  • RFC 7831: Application Bridging for Federated Access Beyond Web (ABFAB) Architecture

    Informational
  • RFC 7832: Application Bridging for Federated Access Beyond Web (ABFAB) Use Cases

    Informational
  • RFC 7833: A RADIUS Attribute, Binding, Profiles, Name Identifier Format, and Confirmation Methods for the Security Assertion Markup Language (SAML)

    Proposed Standard
  • RFC 7804: Salted Challenge Response HTTP Authentication Mechanism

    Experimental
  • RFC 7751: Kerberos Authorization Data Container Authenticated by Multiple Message Authentication Codes (MACs)

    Proposed Standard
  • RFC 7802: A Pseudo-Random Function (PRF) for the Kerberos V Generic Security Service Application Program Interface (GSS-API) Mechanism

    Proposed Standard
  • RFC 7628: A Set of Simple Authentication and Security Layer (SASL) Mechanisms for OAuth

    Proposed Standard
  • RFC 7546: Structure of the Generic Security Service (GSS) Negotiation Loop

    Informational
  • RFC 7055: A GSS-API Mechanism for the Extensible Authentication Protocol

    Proposed Standard
  • RFC 7056: Name Attributes for the GSS-API Extensible Authentication Protocol (EAP) Mechanism

    Proposed Standard
  • RFC 7057: Update to the Extensible Authentication Protocol (EAP) Applicability Statement for Application Bridging for Federated Access Beyond Web (ABFAB)

    Proposed Standard
  • RFC 6680: Generic Security Service Application Programming Interface (GSS-API) Naming Extensions

    Proposed Standard
  • RFC 6616: A Simple Authentication and Security Layer (SASL) and Generic Security Service Application Program Interface (GSS-API) Mechanism for OpenID

    Proposed Standard
  • RFC 6595: A Simple Authentication and Security Layer (SASL) and GSS-API Mechanism for the Security Assertion Markup Language (SAML)

    Proposed Standard
  • RFC 6542: Kerberos Version 5 Generic Security Service Application Program Interface (GSS-API) Channel Binding Hash Agility

    Proposed Standard
  • RFC 6339: Context Token Encapsulate/Decapsulate and OID Comparison Functions for the Generic Security Service Application Program Interface (GSS-API)

    Proposed Standard
  • RFC 6331: Moving DIGEST-MD5 to Historic

    Informational
  • RFC 5998: An Extension for EAP-Only Authentication in IKEv2

    Proposed Standard
  • RFC 5801: Using Generic Security Service Application Program Interface (GSS-API) Mechanisms in Simple Authentication and Security Layer (SASL): The GS2 Mechanism Family

    Proposed Standard
  • RFC 5802: Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API Mechanisms

    Proposed Standard
  • RFC 5929: Channel Bindings for TLS

    Proposed Standard
  • RFC 5896: Generic Security Service Application Program Interface (GSS-API): Delegate if Approved by Policy

    Proposed Standard
  • RFC 5653: Generic Security Service API Version 2: Java Bindings Update

    Proposed Standard

    Obsoleted by RFC 8353

  • RFC 5587: Extended Generic Security Service Mechanism Inquiry APIs

    Proposed Standard
  • RFC 5588: Generic Security Service Application Program Interface (GSS-API) Extension for Storing Delegated Credentials

    Proposed Standard
  • RFC 5554: Clarifications and Extensions to the Generic Security Service Application Program Interface (GSS-API) for the Use of Channel Bindings

    Proposed Standard
  • RFC 5403: RPCSEC_GSS Version 2

    Proposed Standard
  • RFC 5178: Generic Security Service Application Program Interface (GSS-API) Internationalization and Domain-Based Service Names and Name Type

    Proposed Standard
  • RFC 5179: Generic Security Service Application Program Interface (GSS-API) Domain-Based Service Names Mapping for the Kerberos V GSS Mechanism

    Proposed Standard
  • RFC 5056: On the Use of Channel Bindings to Secure Channels

    Proposed Standard
  • RFC 4768: Desired Enhancements to Generic Security Services Application Program Interface (GSS-API) Version 3 Naming

    Informational
  • RFC 4752: The Kerberos V5 ("GSSAPI") Simple Authentication and Security Layer (SASL) Mechanism

    Proposed Standard
  • RFC 4462: Generic Security Service Application Program Interface (GSS-API) Authentication and Key Exchange for the Secure Shell (SSH) Protocol

    Proposed Standard
  • RFC 4401: A Pseudo-Random Function (PRF) API Extension for the Generic Security Service Application Program Interface (GSS-API)

    Proposed Standard
  • RFC 4402: A Pseudo-Random Function (PRF) for the Kerberos V Generic Security Service Application Program Interface (GSS-API) Mechanism

    Historic

    Obsoleted by RFC 7802

  • RFC 4178: The Simple and Protected Generic Security Service Application Program Interface (GSS-API) Negotiation Mechanism

    Proposed Standard
  • RFC 4121: The Kerberos Version 5 Generic Security Service Application Program Interface (GSS-API) Mechanism: Version 2

    Proposed Standard
  • RFC 3645: Generic Security Service Algorithm for Secret Key Transaction Authentication for DNS (GSS-TSIG)

    Proposed Standard
  • RFC 2847: LIPKEY - A Low Infrastructure Public Key Mechanism Using SPKM

    Proposed Standard
  • RFC 2853: Generic Security Service API Version 2 : Java Bindings

    Proposed Standard

    Obsoleted by RFC 5653

  • RFC 2773: Encryption using KEA and SKIPJACK

    Experimental
  • RFC 2743: Generic Security Service Application Program Interface Version 2, Update 1

    Proposed Standard
  • RFC 2744: Generic Security Service API Version 2 : C-bindings

    Proposed Standard
  • RFC 2479: Independent Data Unit Protection Generic Security Service Application Program Interface (IDUP-GSS-API)

    Informational
  • RFC 2228: FTP Security Extensions

    Proposed Standard
  • RFC 2078: Generic Security Service Application Program Interface, Version 2

    Proposed Standard

    Obsoleted by RFC 2743

  • RFC 2025: The Simple Public-Key GSS-API Mechanism (SPKM)

    Proposed Standard
  • RFC 1961: GSS-API Authentication Method for SOCKS Version 5

    Proposed Standard
  • RFC 1964: The Kerberos Version 5 GSS-API Mechanism

    Proposed Standard
  • RFC 1507: DASS - Distributed Authentication Security Service

    Experimental
  • RFC 1508: Generic Security Service Application Program Interface

    Proposed Standard

    Obsoleted by RFC 2078

  • RFC 1509: Generic Security Service API : C-bindings

    Proposed Standard

    Obsoleted by RFC 2744

  • RFC 1510: The Kerberos Network Authentication Service (V5)

    Historic

    Obsoleted by RFC 4120, RFC 6649

  • RFC 1511: Common Authentication Technology Overview

    Informational

Subscribe to GSS-API

Get notified when:

  • RFC changes to status, obsoleted by, updates, updated by, or subseries.
  • New RFC added to this subject or below
  • The subject was merged into another.