[19332] in Kerberos_V5_Development
Re: OpenSSL in FIPS mode - MD5 hash in replay cache
daemon@ATHENA.MIT.EDU (Greg Hudson)
Wed Dec 23 00:47:22 2015
To: Tomas Kuthan <tomas.kuthan@oracle.com>, krbdev@mit.edu
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <567A3560.1060005@mit.edu>
Date: Wed, 23 Dec 2015 00:47:12 -0500
MIME-Version: 1.0
In-Reply-To: <5679DD32.5020609@oracle.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On 12/22/2015 06:30 PM, Tomas Kuthan wrote:
> Is there a reason not to use a new extension identifier 'SHA1:' as I
> proposed originally?
No, you've convinced me.
> I would have also preferred SHA-256 (+ it was pointed out to me in an
> internal discussion twice), but as you say, it is not currently
> available. New checksum type for SHA-256 would be warmly welcomed.
I will try to figure out what would be necessary to register checksum
type numbers for unkeyed SHA-256, SHA-384, and SHA-512.
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev