Re: _kdc_is_weak_exception() relevance in 2014
Jeffrey Altman <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | Secure Endpoints Inc. |
| Message-ID | <[email protected]> |
On 9/22/2014 3:37 PM, Ken Dreyer wrote: > It seems that _kdc_is_weak_exception() unconditionally allows the KDC > to return a 1DES session key, even if I run the server with > --disable-des. > > Now that AFS has had rxkad-kdf for a while, can we remove > _kdc_is_weak_exception() altogether? > > - Ken Ken, Fewer than 30% of public cells have installed versions of OpenAFS that support rxkad-kdf let alone have deployed non-DES keys. Beyond that there are more than a decade of OpenAFS clients deployed that do not support rxkad-kdf. That being said, Yosemite is not going to have any 1DES support and a future version of Heimdal master is going to also lose 1DES support. In my opinion the kdw_weak_exception() for AFS should remain until 1DES is removed entirely. Jeffrey Altman
smime.p7s
(application/pkcs7-signature, 4.4 KB) - not displayed