Currently@ channel bindings are implemented using an MD5 hash in the Kerberos Version 5 Generic Security Service Application Programming Interface (GSS-API) mechanism (RFC 4121). This document updates RFC 4121 to allow channel bindings using algorithms negotiated based on Kerberos crypto framework as defined in RFC 3961. In addition@ because this update makes use of the last extensible field in the Kerberos client-server exchange message@ extensions are defined to allow future protocol extensions.