Markdown Version | Transcript | Session Recording | Session Materials

Session Date/Time: 23 Jul 2026 09:30 ✎ Suggest a correction

KITTEN

Summary

The KITTEN Working Group met at IETF 126 to discuss the status of active SASL drafts, resolve outstanding feedback on draft-ietf-kitten-sasl-ht, and review two new proposals for Kerberos PKINIT regarding cryptographic deprecation and post-quantum cryptography (PQC) support.

Key Discussion Points

WG Document Status

Alexey Melnikov presented the status of the active working group documents using the Chairs' slides:


draft-ietf-kitten-sasl-ht (Hashed Token SASL Mechanism)

The WGLC for draft-ietf-kitten-sasl-ht has concluded. While the document broke backward compatibility by renaming mechanism names from HT to HT-* (meaning there are currently no active implementations), there is strong interest in implementing it.

Simon Josefsson provided a detailed review, and the following resolutions were discussed:


PKINIT Cryptographic Deprecations and PQC Support

A representative from Red Hat presented updates on two Kerberos-related proposals using the slide deck PKINIT cryptographic deprecations and PQC support.

1. Cryptographic Deprecations in PKINIT

The first proposal aims to formally deprecate outdated and weak algorithms in PKINIT:

2. Post-Quantum Cryptography (PQC) Support in PKINIT

The second proposal introduces post-quantum key encapsulation mechanism (KEM) support to protect PKINIT against "harvest now, decrypt later" attacks:

Decisions and Action Items

Next Steps

Related Documents

draft-ietf-kitten-password-storage, draft-ietf-kitten-sasl-ht, draft-ietf-kitten-scram-2fa