Re: Bug in 1.5.1 KDC is session key selection
Jeffrey Altman <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | Secure Endpoints Inc. |
| Message-ID | <[email protected]> |
On 1/19/2012 8:47 AM, Andreas Haupt wrote: > Hi Jeffrey, > > On Thu, 2012-01-19 at 07:38 -0500, Jeffrey Altman wrote: >> Andreas: >> >> That is a bug in OpenAFS that has been fixed in OpenAFS. >> Heimdal already fixed its bug and 1.5 is performing the selection >> correctly in the absence of a specific request by the application. >> Heimdal should not be issuing session keys with the weakest key type >> when the application is requesting that the KDC use its best judgment. > > OK, so what you are saying is that it was bug in Heimdal version 1.2.1 > to work fine with broken klog.krb5 clients? > > Do I understand you correctly? If you want to consider it a bug that Heimdal 1.2.1 considered DES as the preferred encryption type, then yes. Times have changed. DES has been deprecated for use in most systems for almost a decade. In 2012, DES is off by default if supported at all. The fact that it worked was luck. Jeffrey Altman
signature.asc
(application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (MingW32) iQEcBAEBAgAGBQJPGD3cAAoJENxm1CNJffh4lFIH/i/tb05PnjSCuQ+Pslpz1oJY zpHJtULuuJyEb584ozd2NjP2RzA3JfzkDHWKv1KvdHCPT7HM03RXtyE2VDapgxzp JgQne7uroefPTyiGRANmE8DEQv78gl1zZ3/h2CnKe0HEzUEG84gzNwFiYoefCuFf Yjl9sLvD0auzI4s5ehpOiiTY5B4RnJU1jY4wDYJe6InCWTlfEDkDwR1nSdji+Y1F sF3biM04VIL32W7gkGtImXmiz8T0VvoIPlhHpDonHt2pr4sPpFi67cStGw3GLpMy xeU07WEx179IgNwPxxyQKQv2OZzf7A+OVR2DxWLboofCuR4lAL4zPPZhJUh5k/4= =b+1S -----END PGP SIGNATURE-----