Cite this RFC:TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC8070
Discuss this RFC: Send questions or comments to the mailing listkitten@ietf.org
Other actions:Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 8070
This document describes how to further extend the Public KeyCryptography for Initial Authentication in Kerberos (PKINIT)extension (defined in RFC 4556) to exchange an opaque data blob thata Key Distribution Center (KDC) can validate to ensure that theclient is currently in possession of the private key during a PKINITAuthentication Service (AS) exchange.
For the definition ofStatus,seeRFC 2026.
For the definition ofStream, seeRFC 8729.