Re: Subsession keys (Re: KINK issue list)
Sam Hartman <[email protected]> Mon, 31 Jan 2005 20:41:30 -0500
| Newsgroups | gmane.ietf.kink |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Michael" == Michael Thomas <[email protected]> writes: Michael> On Thu, 2005-01-27 at 00:17, KAMADA Ken'ichi wrote: >> At Thu, 20 Jan 2005 11:04:48 +0900, >> "KAMADA Ken'ichi" <[email protected]> wrote: >> > >> > [*] Subsession keys (section 5 and 8) >> > >> > Are subsession keys ignored? (Ken Raeburn) >> >> I think they should not be ignored. Michael> I'm hopelessly behind here, but I don't think I saw a Michael> response to this... why should they be taken into Michael> account? We're already mixing in entropy from the kdc and Michael> the ipsec peers. What is more entropy in the form of Michael> subsession keys buying us? Or am I missing the point? What Bill said is one reason. My reason for bringing up the issue is that you are behaving differently than all other Kerberos applications. Kerberos libraries are actually flexible enough to do what your spec currently asks but it requires implementers to specifically handle subkeys that way. If you don't have a reason for being different then please be the same as everyone else. If you do have a reason, explain it and I'll be happy. --Sam