$ Generic Security Service Application Program Interface (GSS-API)
(I) An Internet Standard protocol [R2743] that specifies calling
conventions by which an application (typically another
communication protocol) can obtain authentication, integrity, and
confidentiality security services independently of the underlying
security mechanisms and technologies, thus enabling the
application source code to be ported to different environments.
(Compare: EAP, SASL.)
Tutorial: "A GSS-API caller accepts tokens provided to it by its
local GSS-API implementation and transfers the tokens to a peer on
a remote system; that peer passes the received tokens to its local
GSS-API implementation for processing. The security services
available through GSS-API in this fashion are implementable (and
have been implemented) over a range of underlying mechanisms based
on [symmetric] and [asymmetric cryptography]."