Re: KDC TGT enctype selection question

Ken Hornstein via krbdev <[email protected]> Mon, 04 Dec 2023 17:23:17 -0500
Newsgroups gmane.comp.encryption.kerberos.devel
Message-ID <[email protected]>
>I would go even further and say that it is a design assumption of MIT krb5
>that all KDCs are just separate instances of the same logical instance and are
>assumed to behave "identically" (i.e., with identical configuration).

I'm going to reiterate my earlier statement: THIS IS NOT AN ANSWER TO MY
QUESTION.

>As Nico says, this particular case seems like the KDC knowing that the enctype
>list is sorted strongest-to-weakest, and also knowing that "the KDC" is the
>only entity that can create this ciphertext, so enforcing that the strongest
>key is being used and preventing by construction any brute-force or other
>attacks on krbtgt keys of other enctypes.

I'm a little unclear how you could try brute-forcing the "wrong" TGT key
in this situation without submitting 2^keylength TGT requests.  Again,
it is possible I am missing something.

--Ken

_______________________________________________
krbdev mailing list             [email protected]
https://mailman.mit.edu/mailman/listinfo/krbdev