RFC 4120: The Kerberos Network Authentication Service (V5)
This document provides an overview and specification of Version 5 of the Kerberos protocol, and it obsoletes RFC 1510 to clarify aspects of the protocol and…
Read RFC 4120 on the RFC Editor
Outgoing relationships (1 related RFC)
Incoming relationships (47 related RFCs)
- Updated by — RFC 6113: A Generalized Framework for Kerberos Pre-Authentication
- Updated by, Normatively referenced by — RFC 6112: Anonymity Support for Kerberos
- Updated by, Normatively referenced by — RFC 5021: Extended Kerberos Version 5 Key Distribution Center (KDC) Exchanges over TCP
- Updated by, Normatively referenced by — RFC 6111: Additional Kerberos Naming Constraints
- Updated by, Normatively referenced by — RFC 6649: Deprecate DES, RC4-HMAC-EXP, and Other Weak Cryptographic Algorithms in Kerberos
- Updated by — RFC 8429: Deprecate Triple-DES (3DES) and RC4 in Kerberos
- Updated by — RFC 8553: DNS Attrleaf Changes: Fixing Specifications That Use Underscored Node Names
- Updated by, Normatively referenced by — RFC 4537: Kerberos Cryptosystem Negotiation Extension
- Updated by, Normatively referenced by — RFC 5896: Generic Security Service Application Program Interface (GSS-API): Delegate if Approved by Policy
- Updated by, Normatively referenced by — RFC 6806: Kerberos Principal Name Canonicalization and Cross-Realm Referrals
- Updated by — RFC 7751: Kerberos Authorization Data Container Authenticated by Multiple Message Authentication Codes (MACs)
- Updated by, Normatively referenced by — RFC 8062: Anonymity Support for Kerberos
- Updated by — RFC 8129: Authentication Indicator in Kerberos Tickets
- Normatively referenced by — RFC 4121: The Kerberos Version 5 Generic Security Service Application Program Interface (GSS-API) Mechanism: Version 2
- Normatively referenced by — RFC 4556: Public Key Cryptography for Initial Authentication in Kerberos (PKINIT)
- Normatively referenced by — RFC 4752: The Kerberos V5 ("GSSAPI") Simple Authentication and Security Layer (SASL) Mechanism
- Normatively referenced by — RFC 7143: Internet Small Computer System Interface (iSCSI) Protocol (Consolidated)
- Normatively referenced by — RFC 8881: Network File System (NFS) Version 4 Minor Version 1 Protocol
- Normatively referenced by — RFC 4430: Kerberized Internet Negotiation of Keys (KINK)
- Normatively referenced by — RFC 8907: The Terminal Access Controller Access-Control System Plus (TACACS+) Protocol
- Normatively referenced by — RFC 4545: Definitions of Managed Objects for IP Storage User Identity Authorization
- Normatively referenced by — RFC 5179: Generic Security Service Application Program Interface (GSS-API) Domain-Based Service Names Mapping for the Kerberos V GSS Mechanism
- Normatively referenced by — RFC 5349: Elliptic Curve Cryptography (ECC) Support for Public Key Cryptography for Initial Authentication in Kerberos (PKINIT)
- Normatively referenced by — RFC 6251: Using Kerberos Version 5 over the Transport Layer Security (TLS) Protocol
- Normatively referenced by — RFC 5868: Problem Statement on the Cross-Realm Operation of Kerberos
- Normatively referenced by — RFC 6448: The Unencrypted Form of Kerberos 5 KRB-CRED Message
- Normatively referenced by — RFC 6717: kx509 Kerberized Certificate Issuance Protocol in Use in 2012
- Normatively referenced by — RFC 6784: Kerberos Options for DHCPv6
- Normatively referenced by — RFC 6880: An Information Model for Kerberos Version 5
- Normatively referenced by — RFC 8070: Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) Freshness Extension
- Normatively referenced by — RFC 9588: Kerberos Simple Password-Authenticated Key Exchange (SPAKE) Pre-authentication
- Informatively referenced by — RFC 5440: Path Computation Element (PCE) Communication Protocol (PCEP)
- Informatively referenced by — RFC 5077: Transport Layer Security (TLS) Session Resumption without Server-Side State
- Informatively referenced by — RFC 5056: On the Use of Channel Bindings to Secure Channels
- Informatively referenced by — RFC 5755: An Internet Attribute Certificate Profile for Authorization
- Informatively referenced by — RFC 6819: OAuth 2.0 Threat Model and Security Considerations
- Informatively referenced by — RFC 5218: What Makes for a Successful Protocol?
- Informatively referenced by — RFC 6528: Defending against Sequence Number Attacks
- Informatively referenced by — RFC 6281: Understanding Apple's Back to My Mac (BTMM) Service
- Informatively referenced by — RFC 4462: Generic Security Service Application Program Interface (GSS-API) Authentication and Key Exchange for the Secure Shell (SSH) Protocol
- Informatively referenced by — RFC 4507: Transport Layer Security (TLS) Session Resumption without Server-Side State
- Informatively referenced by — RFC 4768: Desired Enhancements to Generic Security Services Application Program Interface (GSS-API) Version 3 Naming
- Informatively referenced by — RFC 6680: Generic Security Service Application Programming Interface (GSS-API) Naming Extensions
- Informatively referenced by — RFC 7712: Domain Name Associations (DNA) in the Extensible Messaging and Presence Protocol (XMPP)
- Informatively referenced by — RFC 8000: Requirements for NFSv4 Multi-Domain Namespace Deployment
- Informatively referenced by — RFC 5981: Authorization for NSIS Signaling Layer Protocols
- Informatively referenced by — RFC 8009: AES Encryption with HMAC-SHA2 for Kerberos 5