Re: Subsession keys (Re: KINK issue list)

Sam Hartman <[email protected]> Mon, 31 Jan 2005 20:41:30 -0500
Newsgroups gmane.ietf.kink
Message-ID <[email protected]>
>>>>> "Michael" == Michael Thomas <[email protected]> writes:

    Michael> On Thu, 2005-01-27 at 00:17, KAMADA Ken'ichi wrote:
    >> At Thu, 20 Jan 2005 11:04:48 +0900,
    >> "KAMADA Ken'ichi" <[email protected]> wrote:
    >> > 
    >> > [*] Subsession keys (section 5 and 8)
    >> > 
    >> > Are subsession keys ignored?  (Ken Raeburn)
    >> 
    >> I think they should not be ignored.

    Michael> I'm hopelessly behind here, but I don't think I saw a
    Michael> response to this... why should they be taken into
    Michael> account? We're already mixing in entropy from the kdc and
    Michael> the ipsec peers. What is more entropy in the form of
    Michael> subsession keys buying us? Or am I missing the point?

What Bill said is one reason.

My reason for bringing up the issue is that you are behaving
differently than all other Kerberos applications.  Kerberos libraries
are actually flexible enough to do what your spec currently asks but
it requires implementers to specifically handle subkeys that way.

If you don't have a reason for being different then please be the same
as everyone else.  If you do have a reason, explain it and I'll be
happy.


--Sam