RFC 2808 (rfc2808) - Page 1 of 11


The SecurID(r) SASL Mechanism



Alternative Format: Original Text Document



Network Working Group                                        M. Nystrom
Request for Comments: 2808                             RSA Laboratories
Category: Informational                                      April 2000


                     The SecurID(r) SASL Mechanism

Status of this Memo

   This memo provides information for the Internet community.  It does
   not specify an Internet standard of any kind.  Distribution of this
   memo is unlimited.

Copyright Notice

   Copyright (C) The Internet Society (2000).  All Rights Reserved.

Abstract

   SecurID is a hardware token card product (or software emulation
   thereof) produced by RSA Security Inc., which is used for end-user
   authentication. This document defines a SASL [RFC 2222] authentication
   mechanism using these tokens, thereby providing a means for such
   tokens to be used in SASL environments. This mechanism is only for
   authentication, and has no effect on the protocol encoding and is not
   designed to provide integrity or confidentiality services.

   This memo assumes the reader has basic familiarity with the SecurID
   token, its associated authentication protocol and SASL.

How to read this document

   The key words "MUST", "MUST NOT", "SHALL", "SHOULD" and "MAY" in this
   document are to be interpreted as defined in [RFC 2119].

   In examples, "C:" and "S:" indicate messages sent by the client and
   server respectively.

1. Introduction

   The SECURID SASL mechanism is a good choice for usage scenarios where
   a client, acting on behalf of a user, is untrusted, as a one-time
   passcode will only give the client a single opportunity to act
   maliciously. This mechanism provides authentication only.







Nystrom                      Informational