摘要
Kerberos 认证可以有效地防止重放攻击,文章在对Kerberos协议分析的基础上,介绍了Kerberos 认证在SSL中的应用。
This paper introduces mechanisms for supporting Kerberos [KERB] authentication within the SSL protocol, and extends RFC 2712 to support delegation of Kerberos credentials. In this way, a SSL server may obtain a Kerberos service ticket on behalf of the SSL client. Thus, a single client identity may be used for authentication within a multi-tier architecture. This paper also proposes a mechanism for a SSL server to indicate Kerberos-specific information to the client within the certificate request message in the initial exchange.
出处
《计算机工程》
CAS
CSCD
北大核心
2002年第11期167-169,共3页
Computer Engineering