-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathad-type
55 lines (50 loc) · 2.29 KB
/
ad-type
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
This file contains registrations of Kerberos ad-type values. Send
email to ghudson@mit.edu with corrections or requests for new
assignments.
Each entry should contain:
* A number
* A reference to the governing standard, with section number
* A symbolic constant name from the governing standard, preferrably
the name of the ASN.1 type associated with the number (usually in
uppercase with hyphens)
A number may have multiple entries if there is a conflict. The only
known conflicts are for ad-type 142, which has been resolved by moving
AD-SIGNTICKET to ad-type 512, and ad-type 143, where the conflict can
easily be resolved based on the type of protocol operation.
1 AD-IF-RELEVANT (rfc4120 7.5.4)
2 AD-INTENDED-FOR-SERVER (rfc4120 7.5.4)
3 AD-INTENDED-FOR-APPLICATION-CLASS (rfc4120 7.5.4)
4 AD-KDC-ISSUED (rfc4120 7.5.4)
5 AD-AND-OR (rfc4120 7.5.4)
6 AD-MANDATORY-TICKET-EXTENSIONS (rfc4120 7.5.4)
7 AD-IN-TICKET-EXTENSIONS (rfc4120 7.5.4)
8 AD-MANDATORY-FOR-KDC (rfc4120 7.5.4)
9 AD_INITIAL_VERIFIED_CAS (rfc4556 3.1.2)
10-63 reserved (rfc4120 7.5.4)
64 OSF-DCE (rfc4120 7.5.4)
65 SESAME (rfc4120 7.5.4)
66 AD-OSF-DCE-PKI-CERTID (rfc4120 7.5.4)
70 AD-authentication-strength (rfc6113 5.5)
71 AD-fx-fast-armor (rfc6113 5.4.1.1)
72 AD-fx-fast-used (rfc6113 5.4.2)
80 AD-LOGIN-ALIAS (rfc6806 6)
96 AD-CAMMAC (rfc7751 4)
97 AD-AUTHENTICATION-INDICATOR (rfc8129 3)
128 AD-WIN2K-PAC (rfc4120 7.5.4, MS-PAC)
129 AD-ETYPE-NEGOTIATION (rfc4120 7.5.4, rfc4537 3)
130 reserved (AD-AP-REP-USE-SUBKEY, details forthcoming)
141 KERB-AD-RESTRICTION-ENTRY (MS-KILE 2.2.6)
142 KERB-LOCAL (MS-KILE 2.2.4)
143 AD-AUTH-DATA-AP-OPTIONS (MS-KILE 3.2.5.8)
143 ad-pku2u-client-name (draft-zhu-pku2u-09 6.3)
144 reserved (Microsoft; details unknown)
145 reserved (Microsoft; details unknown)
512 AD-SIGNTICKET (MIT krb5 and Heimdal S4U2Self evidence ticket)
513 AD-DIAMETER (draft-vanrein-krb5-authzdata-diameter-01 2)
580 AD-ON-BEHALF-OF (Heimdal for RFC6717 updates)
581 AD-BEARER-TOKEN-JWT (Heimdal for RFC6717 updates)
582 AD-BEARER-TOKEN-SAML (Heimdal for RFC6717 updates)
583 AD-BEARER-TOKEN-OIDC (Heimdal for RFC6717 updates)
584 AD-CERT-REQ-AUTHORIZED (Heimdal for RFC6717 updates)
The following are outdated or deprecated assignments:
142 AD-SIGNTICKET-OLD (conflicted with Microsoft)