RFC 2808 (rfc2808) - Page 1 of 11
The SecurID(r) SASL Mechanism
Alternative Format: Original Text Document
Network Working Group M. Nystrom
Request for Comments: 2808 RSA Laboratories
Category: Informational April 2000
The SecurID(r) SASL Mechanism
Status of this Memo
This memo provides information for the Internet community. It does
not specify an Internet standard of any kind. Distribution of this
memo is unlimited.
Copyright Notice
Copyright (C) The Internet Society (2000). All Rights Reserved.
Abstract
SecurID is a hardware token card product (or software emulation
thereof) produced by RSA Security Inc., which is used for end-user
authentication. This document defines a SASL [RFC 2222] authentication
mechanism using these tokens, thereby providing a means for such
tokens to be used in SASL environments. This mechanism is only for
authentication, and has no effect on the protocol encoding and is not
designed to provide integrity or confidentiality services.
This memo assumes the reader has basic familiarity with the SecurID
token, its associated authentication protocol and SASL.
How to read this document
The key words "MUST", "MUST NOT", "SHALL", "SHOULD" and "MAY" in this
document are to be interpreted as defined in [RFC 2119].
In examples, "C:" and "S:" indicate messages sent by the client and
server respectively.
1. Introduction
The SECURID SASL mechanism is a good choice for usage scenarios where
a client, acting on behalf of a user, is untrusted, as a one-time
passcode will only give the client a single opportunity to act
maliciously. This mechanism provides authentication only.
Nystrom Informational