[19299] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: RFC 6542 adopted by MIT krb5?

daemon@ATHENA.MIT.EDU (Wang Weijun)
Thu Oct 15 21:52:38 2015

Mime-Version: 1.0 (Mac OS X Mail 9.0 \(3093\))
From: Wang Weijun <weijun.wang@oracle.com>
In-Reply-To: <561FE9CD.6080105@mit.edu>
Date: Fri, 16 Oct 2015 09:52:06 +0800
Message-Id: <2C61E11E-7BD1-406D-BE76-ECA1258B1C65@oracle.com>
To: Greg Hudson <ghudson@mit.edu>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu


> On Oct 16, 2015, at 2:00 AM, Greg Hudson <ghudson@mit.edu> wrote:
> 
> On 10/15/2015 04:00 AM, Wang Weijun wrote:
>> We (Java team at Oracle) are going through weak algorithms in all our code and noticed our krb5 GSS-API mech is using MD5 in channel binding. I noticed RFC 6542 already updated it. Does MIT krb5 support it?
> 
> To the best of my knowledge, we haven't implemented it yet.

Is there a plan?

The TLS guys in our team are talking about removing SHA-1 and I am asked what we can do on Kerberos. I said we only need for a little while because the SHA-2 related etypes are already in an IETF draft. And then I notice we are still using MD5. :-(

--Max


_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post