Re: Bug in 1.5.1 KDC is session key selection

Jeffrey Altman <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Organization Secure Endpoints Inc.
Message-ID <[email protected]>
On 1/19/2012 8:47 AM, Andreas Haupt wrote:
> Hi Jeffrey,
> 
> On Thu, 2012-01-19 at 07:38 -0500, Jeffrey Altman wrote:
>> Andreas:
>>
>> That is a bug in OpenAFS that has been fixed in OpenAFS.
>> Heimdal already fixed its bug and 1.5 is performing the selection
>> correctly in the absence of a specific request by the application.
>> Heimdal should not be issuing session keys with the weakest key type
>> when the application is requesting that the KDC use its best judgment.
> 
> OK, so what you are saying is that it was bug in Heimdal version 1.2.1
> to work fine with broken klog.krb5 clients?
> 
> Do I understand you correctly?

If you want to consider it a bug that Heimdal 1.2.1 considered DES as
the preferred encryption type, then yes.

Times have changed.  DES has been deprecated for use in most systems for
almost a decade.  In 2012, DES is off by default if supported at all.
The fact that it worked was luck.

Jeffrey Altman
signature.asc (application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)

iQEcBAEBAgAGBQJPGD3cAAoJENxm1CNJffh4lFIH/i/tb05PnjSCuQ+Pslpz1oJY
zpHJtULuuJyEb584ozd2NjP2RzA3JfzkDHWKv1KvdHCPT7HM03RXtyE2VDapgxzp
JgQne7uroefPTyiGRANmE8DEQv78gl1zZ3/h2CnKe0HEzUEG84gzNwFiYoefCuFf
Yjl9sLvD0auzI4s5ehpOiiTY5B4RnJU1jY4wDYJe6InCWTlfEDkDwR1nSdji+Y1F
sF3biM04VIL32W7gkGtImXmiz8T0VvoIPlhHpDonHt2pr4sPpFi67cStGw3GLpMy
xeU07WEx179IgNwPxxyQKQv2OZzf7A+OVR2DxWLboofCuR4lAL4zPPZhJUh5k/4=
=b+1S
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.