Simple Authentication and Security Layer

From Wikipedia, the free encyclopedia - View original article

 
Jump to: navigation, search

Simple Authentication and Security Layer (SASL) is a framework for authentication and data security in Internet protocols. It decouples authentication mechanisms from application protocols, in theory allowing any authentication mechanism supported by SASL to be used in any application protocol that uses SASL. Authentication mechanisms can also support proxy authorization, a facility allowing one user to assume the identity of another. They can also provide a data security layer offering data integrity and data confidentiality services. DIGEST-MD5 provides an example of mechanisms which can provide a data-security layer. Application protocols that support SASL typically also support Transport Layer Security (TLS) to complement the services offered by SASL. In 1997, John Gardiner Myers wrote the original SASL specification (RFC 2222) while at Carnegie Mellon University. In 2006 that document was made obsolete by RFC 4422, edited by Alexey Melnikov and Kurt Zeilenga.

SASL is an IETF Standard Track protocol and is, as of 2010, a Proposed Standard.

SASL mechanisms[edit]

A SASL mechanism implements a series of challenges and responses. Defined SASL mechanisms[1] include:

The GS2 family of mechanisms supports arbitrary GSS-API mechanisms in SASL.[5] It is now standardized as RFC 5801.

SASL-aware application protocols[edit]

Application protocols define their representation of SASL exchanges with a profile. A protocol has a service name such as "ldap" in a registry shared with GSSAPI and Kerberos.[6]

As of 2012 protocols currently supporting SASL include:

See also[edit]

External links[edit]

References[edit]

  1. ^ SASL mechanisms
  2. ^ RFC 6331
  3. ^ Luke Howard. "A SASL and GSS-API Mechanism for the BrowserID Authentication Protocol". 
  4. ^ Sam Hartman. "A GSS-API Mechanism for the Extensible Authentication Protocol". 
  5. ^ Simon Josefsson. "Using GSS-API Mechanisms in SASL: The GS2 Mechanism Family". 
  6. ^ GSSAPI/Kerberos/SASL Service names
  7. ^ Request for allocation of new security type code for SASL auth
  8. ^ Bartlett, Andrew (2005-04-25). "GENSEC - Designing a security subsystem" (PDF). p. 4. Retrieved 2010-03-28. "The idea of a generic security API is not new [...] to implement, by some mechanism or other, a wide variety of these protocols, including SASL, GSS-API, SPNEGO as well as the proprietary NTLMSSP [...] in the wider open source world we see individual applications introduce similar abstraction layers, or adopt the Open Source Cyrus-SASL library to provide one."