[19850] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: After RFC 8429: Deprecate Triple-DES (3DES) and RC4 in Kerberos

daemon@ATHENA.MIT.EDU (Greg Hudson)
Fri Nov 2 23:45:54 2018

To: Weijun Wang <weijun.wang@oracle.com>
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <977713ce-36c9-777b-4ff1-01ae13787a9e@mit.edu>
Date: Fri, 2 Nov 2018 23:45:32 -0400
MIME-Version: 1.0
In-Reply-To: <F912D726-1E79-45A4-8FC6-0031BF563A05@oracle.com>
Content-Language: en-US
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 11/01/2018 10:30 AM, Weijun Wang wrote:
> Now that RFC 8429 is published and 3DES and RC4 are deprecated, is there any plan to remove them from etype list of KDC-REQ?

For RC4, I would like Microsoft to take the lead.  3DES is our 
responsibility, and is probably not in nearly as much use (although I'd 
have to at least check if we're still using it internally at MIT), so it 
is probably not as painful to deprecate.

There is some ambiguity in how weak an enctype needs to be to qualify 
for being affected by allow_weak_crypto.  The primary concerns about 
des3-cbc-sha1 are its 64-bit block size and the fast speed of its 
string-to-key operation; both of these are far less problematic than the 
practical ability to recover a random single-DES key.  It would also be 
a shame if administrators wound up enabling DES in order to make DES3 
work (or RC4).
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post