| |
| | [No title] |
 | | Mechanisms may be able to compute PRFs with security contexts that - are not fully established, therefore applications MAY call + are not fully established, therefore applications may call GSS_Pseudo_random() with such security contexts. |
 | | Mechanisms that allow for PRF computation prior to - full security context establishment MUST use the same PRF and key - material, for any given security context, both, before and after full - context establishment, and the PRF and key material negotiation MUT + PRF computation using the requested prf_key. |
 | | Some mechanisms may support the GSS PRF function with security contexts that are not fully established, but applications MUST assume that authentication, mutual or otherwise, has not completed until the security context is fully established 5. |
| blogs.sun.com /roller/resources/nico/kitten-gss-prf.02_03.diffs (1536 words) |
|