Movatterモバイル変換


[0]ホーム

URL:


Search RFCs

Advanced Search

RFC Editor

RFC 4169

Hypertext Transfer Protocol (HTTP) Digest Authentication Using Authentication and Key Agreement (AKA) Version-2,November 2005

File formats:
icon for text fileicon for PDFicon for HTML
Status:
INFORMATIONAL
Authors:
V. Torvinen
J. Arkko
M. Naslund
Stream:
IETF
Source:
NON WORKING GROUP

Cite this RFC:TXT  | XML  |  BibTeX

DOI:  https://doi.org/10.17487/RFC4169

Discuss this RFC: Send questions or comments to the mailing listiesg@ietf.org

Other actions:Submit Errata  | Find IPR Disclosures from the IETF  | View History of RFC 4169


Abstract

HTTP Digest, as specified in RFC 2617, is known to be vulnerable toman-in-the-middle attacks if the client fails to authenticate theserver in TLS, or if the same passwords are used for authenticationin some other context without TLS. This is a general problem thatexists not just with HTTP Digest, but also with other IETF protocolsthat use tunneled authentication. This document specifies version 2of the HTTP Digest AKA algorithm (RFC 3310). This algorithm can beimplemented in a way that it is resistant to the man-in-the-middleattack. This memo provides information for the Internet community.


For the definition ofStatus,seeRFC 2026.

For the definition ofStream, seeRFC 8729.




IABIANAIETFIRTFISEISOCIETF Trust
ReportsPrivacy StatementSite MapContact Us

Advanced Search

[8]ページ先頭

©2009-2026 Movatter.jp