[19300] in Kerberos_V5_Development
Re: RFC 6542 adopted by MIT krb5?
daemon@ATHENA.MIT.EDU (Benjamin Kaduk)
Thu Oct 15 22:22:57 2015
Date: Thu, 15 Oct 2015 22:22:45 -0400 (EDT)
From: Benjamin Kaduk <kaduk@mit.edu>
To: Wang Weijun <weijun.wang@oracle.com>
In-Reply-To: <2C61E11E-7BD1-406D-BE76-ECA1258B1C65@oracle.com>
Message-ID: <alpine.GSO.1.10.1510152221090.26829@multics.mit.edu>
MIME-Version: 1.0
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On Thu, 15 Oct 2015, Wang Weijun wrote:
>
> The TLS guys in our team are talking about removing SHA-1 and I am asked
> what we can do on Kerberos. I said we only need for a little while
> because the SHA-2 related etypes are already in an IETF draft. And then
> I notice we are still using MD5. :-(
It will be more than "a little while" before the SHA-2 enctypes are widely
deployed, I fear. Of course, the SHA-1 ones use HMAC-SHA1, but it is
harder to convince people that HMAC is different than to have an
alternative deployed.
-Ben
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev