Re: _kdc_is_weak_exception() relevance in 2014

Jeffrey Altman <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Organization Secure Endpoints Inc.
Message-ID <[email protected]>
On 9/22/2014 3:37 PM, Ken Dreyer wrote:
> It seems that _kdc_is_weak_exception() unconditionally allows the KDC
> to return a 1DES session key, even if I run the server with
> --disable-des.
> 
> Now that AFS has had rxkad-kdf for a while, can we remove
> _kdc_is_weak_exception() altogether?
> 
> - Ken


Ken,

Fewer than 30% of public cells have installed versions of OpenAFS that
support rxkad-kdf let alone have deployed non-DES keys.

Beyond that there are more than a decade of OpenAFS clients deployed
that do not support rxkad-kdf.

That being said, Yosemite is not going to have any 1DES support and a
future version of Heimdal master is going to also lose 1DES support.  In
my opinion the kdw_weak_exception() for AFS should remain until 1DES is
removed entirely.

Jeffrey Altman
smime.p7s (application/pkcs7-signature, 4.4 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.