RFC 3645:Generic Security Service Algorithm for ...
RFC-Ref

algorithm


Click on the red underlined text to get to the source

... TSIG protocol [RFC2845] is extensible through the definition of new algorithms. This document specifies an algorithm based on the Generic Security Service Application Program Interface ...
... RFC2845] is extensible through the definition of new algorithms. This document specifies an algorithm based on the Generic Security Service Application Program Interface (GSS-API ...


... Algorithm Overview ...
... The GSS-TSIG algorithm consists of two stages: I. Establish security context ...
... queries MUST be explicitly specified in the description of an individual secret key establishment algorithm." ...


... then the client MUST abandon the algorithm and MUST NOT use the GSS- TSIG ...
... GSS- TSIG algorithm to establish this security context. This document does not prescribe which other mechanism could be used to establish a ...
... client MAY use GSS-TSIG algorithm. Success values of major_status are GSS ...
... both of these values are FALSE, the client MUST abandon this algorithm. Client ...
... RDATA Algorithm Name = gss-tsig Mode = 3 (GSS-API negotiation ...


... query with QTYPE = TKEY, the server MUST examine whether the Mode and Algorithm Name fields of the TKEY record in the additional records section of the message contain values of 3 and ...
... RDATA Algorithm Name = gss-tsig Mode = 3 (GSS-API negotiation ...


... RDATA Algorithm Name = gss-tsig Assign the remaining fields in the TSIG ...
... For the GSS algorithm, a signature is verified by using GSS ...


... Example usage of GSS-TSIG algorithm ...
... and a Server, server.example.com, establish a security context according to the algorithm described above. I. Client ...
... (Note that some INPUT and OUTPUT parameters not critical for this algorithm are not described in this example.) CONTEXT ...
... TKEY record in its Additional records section with the following fields. (Note that some fields not specific to this algorithm are not specified.) NAME = 789.client ...
... RDATA Algorithm Name = gss-tsig Mode = 3 (GSS-API negotiation ...
... query with QTYPE = TKEY, the server verifies that Mode and Algorithm fields in the TKEY record in the Additional records section of the query ...
... context with the following parameters. (Note that some INPUT and OUTPUT parameters not critical for this algorithm are not described in this example.) ...
... (Note that some INPUT and OUTPUT parameters not critical for this algorithm are not described in this example.) CONTEXT ...
... fields. (Note that some INPUT and OUTPUT parameters not critical to this algorithm are not described in this example.) NAME = 789.client ...
... RDATA Algorithm Name = gss-tsig Mode = 3 (GSS-API negotiation ...
... TKEY query, the server verifies that Mode and Algorithm fields in the TKEY record in the Additional records section of the query ...
... context with the following parameters (Note that some INPUT and OUTPUT parameters not critical for this algorithm are not described in this example) ...


... The IANA has reserved the TSIG Algorithm name gss-tsig for the use in the Algorithm fields of TKEY ...
... TSIG Algorithm name gss-tsig for the use in the Algorithm fields of TKEY and TSIG resource records ...
... TSIG resource records. This Algorithm name refers to the algorithm described in this document. The requirement ...
... resource records. This Algorithm name refers to the algorithm described in this document. The requirement to have this name registered with IANA ...



Google
Web
RFC-Ref