@techreport{santesson-tls-gssapi-03, number = {draft-santesson-tls-gssapi-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-santesson-tls-gssapi/03/}, author = {Larry Zhu and Girish Chander and Jeffrey E. Altman and Stefan Santesson}, title = {{Flexible Key Agreement for Transport Layer Security (FKA-TLS)}}, pagetotal = 16, year = 2007, month = jul, day = 25, abstract = {This document defines extensions to RFC 4279, "Pre-Shared Key Ciphersuites for Transport Layer Security (TLS)", to enable dynamic key sharing in distributed environments using a Generic Security Service Application Program Interface (GSS-API) mechanism, and then import that shared key as the "Pre-Shared Key" to complete the TLS handshake. This is a modular approach to perform authentication and key exchange based on off-shelf libraries. And it obviates the need of pair-wise key sharing by enabling the use of the widely-deployed Kerberos alike trust infrastructures that are highly scalable and robust. Furthermore, conforming implementations can provide server authentication without the use of certificates.}, }