[19853] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: After RFC 8429: Deprecate Triple-DES (3DES) and RC4 in Kerberos

daemon@ATHENA.MIT.EDU (Benjamin Kaduk)
Mon Nov 5 11:04:30 2018

Date: Mon, 5 Nov 2018 10:04:12 -0600
From: Benjamin Kaduk <kaduk@mit.edu>
To: Derek Atkins <derek@ihtfp.com>
Message-ID: <20181105160412.GJ54966@kduck.kaduk.org>
MIME-Version: 1.0
Content-Disposition: inline
In-Reply-To: <sjmmuqnbjpd.fsf@securerf.ihtfp.org>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Mon, Nov 05, 2018 at 10:57:50AM -0500, Derek Atkins wrote:
> Greg Hudson <ghudson@mit.edu> writes:
> 
> > On 11/01/2018 10:30 AM, Weijun Wang wrote:
> >> Now that RFC 8429 is published and 3DES and RC4 are deprecated, is
> >> there any plan to remove them from etype list of KDC-REQ?
> >
> > For RC4, I would like Microsoft to take the lead.  3DES is our 
> > responsibility, and is probably not in nearly as much use (although I'd 
> > have to at least check if we're still using it internally at MIT), so it 
> > is probably not as painful to deprecate.
> >
> > There is some ambiguity in how weak an enctype needs to be to qualify 
> > for being affected by allow_weak_crypto.  The primary concerns about 
> > des3-cbc-sha1 are its 64-bit block size and the fast speed of its 
> > string-to-key operation; both of these are far less problematic than the 
> > practical ability to recover a random single-DES key.  It would also be 
> > a shame if administrators wound up enabling DES in order to make DES3 
> > work (or RC4).
> 
> Maybe we need an "allow_very_weak_crypto" in addition to the
> "allow_weak_crypto"?

Perhaps ... though what is keeping us from biting the bullet and just not
exposing single-DES at all (forcing sites that need it to stay on an old
software branch)?

-Ben
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post