Options for Abfab-based Kerberos pre-authentication

Document Type Expired Internet-Draft (individual)
Authors Alejandro Pérez-Méndez  , Josh Howlett 
Last updated 2012-09-13 (latest revision 2012-03-12)
Stream (None)
Intended RFC status (None)
Expired & archived
pdf htmlized bibtex
Stream Stream state (No stream defined)
Consensus Boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


Kerberos is widely used for authentication within organisations. It is not, however, commonly used for authentication between domains or realms ("cross-realm operation"). Abfab is a new architecture, based on the AAA framework, that provides a mechanism for federating authentication between realms. AAA protocols are already widely used for federating authentication for network access scenarios today. It has been proposed that Abfab could be used to provide a mechanism yielding cross-realm functionality for Kerberos. This document discusses two alternative models with the aim of informing and facilitating discussion.


Alejandro Pérez-Méndez (alex@um.es)
Josh Howlett (josh.howlett@ja.net)

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)