[19294] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: krb5-1.14-beta1 is available

daemon@ATHENA.MIT.EDU (Tom Yu)
Fri Oct 9 21:14:03 2015

From: Tom Yu <tlyu@mit.edu>
To: Wang Weijun <weijun.wang@oracle.com>
Date: Fri, 09 Oct 2015 21:13:55 -0400
In-Reply-To: <93274EFE-B81A-46D3-B9C9-7518DFD3AC98@oracle.com> (Wang Weijun's
	message of "Sat, 10 Oct 2015 09:03:21 +0800")
Message-ID: <ldvsi5jcyp8.fsf@sarnath.mit.edu>
MIME-Version: 1.0
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

This is a challenging to explain concisely, but basically in Kerberos,
3DES and RC4 are still reasonably strong for randomly generated keys but
not for password-derived ones.

krb5-devel/doc is master, not the release branch, but it's close enough
for now.

-Tom

Wang Weijun <weijun.wang@oracle.com> writes:

> You mean all 3DES and RC4 etypes as described in https://tools.ietf.org/html/draft-kaduk-kitten-des-des-des-die-die-die-00? I see 16 and 23 still not marked weak in http://web.mit.edu/kerberos/krb5-devel/doc/admin/conf_files/kdc_conf.html#encryption-types.
>
> BTW, is the krb5-devel/doc pages always synced with the latest public beta?
>
> Thanks
> Max
>
>> On Oct 10, 2015, at 4:44 AM, Tom Yu <tlyu@mit.edu> wrote:
>> 
>> 
>> * Remove the triple-DES and RC4 encryption types from the default
>>  value of supported_enctypes, which determines the default key and
>>  salt types for new password-derived keys.  By default, keys will
>>  only created only for AES128 and AES256.  This mitigates some types
>>  of password guessing attacks.
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post