[19299] in Kerberos_V5_Development
Re: RFC 6542 adopted by MIT krb5?
daemon@ATHENA.MIT.EDU (Wang Weijun)
Thu Oct 15 21:52:38 2015
Mime-Version: 1.0 (Mac OS X Mail 9.0 \(3093\))
From: Wang Weijun <weijun.wang@oracle.com>
In-Reply-To: <561FE9CD.6080105@mit.edu>
Date: Fri, 16 Oct 2015 09:52:06 +0800
Message-Id: <2C61E11E-7BD1-406D-BE76-ECA1258B1C65@oracle.com>
To: Greg Hudson <ghudson@mit.edu>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
> On Oct 16, 2015, at 2:00 AM, Greg Hudson <ghudson@mit.edu> wrote:
>
> On 10/15/2015 04:00 AM, Wang Weijun wrote:
>> We (Java team at Oracle) are going through weak algorithms in all our code and noticed our krb5 GSS-API mech is using MD5 in channel binding. I noticed RFC 6542 already updated it. Does MIT krb5 support it?
>
> To the best of my knowledge, we haven't implemented it yet.
Is there a plan?
The TLS guys in our team are talking about removing SHA-1 and I am asked what we can do on Kerberos. I said we only need for a little while because the SHA-2 related etypes are already in an IETF draft. And then I notice we are still using MD5. :-(
--Max
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev