Static ReadonlyADThe authorization data types: AD-IF-RELEVANT, RFC 6113's two FAST markers, AD-CAMMAC and AD-AUTHENTICATION-INDICATOR.
Static ReadonlyARMOR_The one FAST armor type defined, an AP-REQ (RFC 6113 section 5.4.1).
Static ReadonlyERRORThe error codes of RFC 6113 section 6.1 and RFC 6560 section 2.3.
Static ReadonlyFAST_The FastOptions bits (RFC 6113 section 5.4.2); bits 0 to 15 are critical.
Static ReadonlyKEY_The key usages: RFC 6560's, RFC 6113's, RFC 7751's, and MIT's private usage for the PA-FX-COOKIE.
Static ReadonlyOTP_The OTPFlags bits (RFC 6560 section 4.1), numbered from the most significant bit.
Static ReadonlyOTP_The otp-format values (RFC 6560).
Static ReadonlyPAThe padata types of RFC 6113 section 6.4 and RFC 6560 section 5.
StaticasReads an implicitly tagged TLV back as the universal type it replaces.
the context-tagged TLV
the universal tag to read it as
the TLV
StaticdecStaticencEncodes a KrbFastArmor.
{ type, value }
the DER
StaticencEncodes an AD-CAMMAC around the already-encoded AuthorizationData its verifiers' MACs cover.
{ elementsBytes, kdcVerifier, svcVerifier }
the DER
StaticencEncodes a KrbFastFinished.
{ timestamp, usec, crealm, cname, ticketChecksum }
the DER
StaticencEncodes a PA-FX-FAST-REPLY around the encrypted KrbFastResponse.
the EncryptedData
the DER
StaticencEncodes a KrbFastReq; a reqBody carrying its raw bytes is placed as
they are.
{ fastOptions, padata, reqBody }
the DER
StaticencEncodes a PA-FX-FAST-REQUEST, a KrbFastArmoredReq in its [0] alternative.
{ armor, reqChecksum, encFastReq }, armor optional
the DER
StaticencEncodes a KrbFastResponse.
{ padata, strengthenKey, finished, nonce }, the middle two
optional
the DER
StaticencEncodes an AD-AUTHENTICATION-INDICATOR.
the indicators
the DER
StaticencEncodes a PA-OTP-CHALLENGE, every tag implicit.
{ nonce, service, tokenInfo, salt, s2kparams }
the DER
StaticencEncodes a PA-OTP-ENC-REQUEST.
the nonce
the DER
StaticencEncodes a PA-OTP-REQUEST, every tag implicit.
{ flags, nonce, encData, value, pin, time, vendor }
the DER
StaticencEncodes a SEQUENCE OF PA-DATA.
the PA-DATA
the DER
StaticencEncodes an OTP-TOKENINFO; the two hashing fields are never written.
{ flags, vendor, challenge, length, format, tokenId, algId }
the DER
StaticencEncodes a UTF8String.
the text
the DER
StaticencEncodes a Verifier-MAC.
{ identifier, kvno, enctype, mac }, all but mac optional
the DER
StaticexplicitStaticfieldsStaticfindReturns the PA-DATA of a type in a list.
the PA-DATA
the padata type
the PA-DATA, or null
StaticiEncodes an implicitly tagged INTEGER field.
the context tag number
the integer
the TLV, or null when absent
StaticimplicitTurns an encoded universal TLV into its implicitly context-tagged form
[n], the constructed bit kept.
the context tag number
the universal TLV
the retagged TLV, or null for null
StaticimplicitStaticimplicitEncodes a SEQUENCE of the fields that are present.
the encoded fields, null for absent
the DER
StaticiEncodes an implicitly tagged OCTET STRING field.
the context tag number
the bytes
the TLV, or null when absent
StaticiEncodes an implicitly tagged UTF8String field.
the context tag number
the text
the TLV, or null when absent
StaticpadataDecodes a SEQUENCE OF PA-DATA.
the SEQUENCE's TLV
the PA-DATA
StaticreadStaticreadStaticreadStaticreadStaticreadStaticreadStaticreadStaticreadStaticreadStaticreadStaticreadStaticreadStaticreadStaticrequired
The wire format of Kerberos FAST (RFC 6113), OTP pre-authentication (RFC 6560) and authentication indicators (RFC 7751, RFC 8129): structures to DER and back, built on the vendored codec's primitives.
It knows no key and no policy; a structure that does not decode throws. A static utility class.