[19837] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Is there a valid case for an empty password?

daemon@ATHENA.MIT.EDU (Weijun Wang)
Thu Oct 11 23:20:34 2018

From: Weijun Wang <weijun.wang@oracle.com>
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
Date: Fri, 12 Oct 2018 11:19:45 +0800
Message-Id: <28177C8B-210D-4FD2-9A1A-226D7D827591@oracle.com>
To: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

We are planning to disallow empty passwords for PBKDF2 in JDK. However, some years ago I did receive a bug report to support empty passwords on Windows 200x. Is it really a valid password?

Thanks
Max


_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post