Re: Subsession keys (Re: KINK issue list)

Michael Thomas <[email protected]> Tue, 01 Feb 2005 08:21:24 -0800
Newsgroups gmane.ietf.kink
Organization Cisco Systems
Message-ID <[email protected]>
On Mon, 2005-01-31 at 17:41, Sam Hartman wrote:
> >>>>> "Michael" == Michael Thomas <[email protected]> writes:

> My reason for bringing up the issue is that you are behaving
> differently than all other Kerberos applications.  Kerberos libraries
> are actually flexible enough to do what your spec currently asks but
> it requires implementers to specifically handle subkeys that way.
> 
> If you don't have a reason for being different then please be the same
> as everyone else.  If you do have a reason, explain it and I'll be
> happy.

I'm sorry, but I'm having a real problem with this guilty
until proven innocent stance. This document was through
several iterations of review from the IESG and just got
dropped on the floor by the IESG. I think it's incumbent 
on those who are throwing darts here to say if there are
REAL PROBLEMS, not just harmonization with the universe.
In this particular case, I had *zero* problem coding this
up. Is there an _actual_ cryptographical problem here, or
is this another trip to the beauty shop? There are people
who have been writing to *this* spec for several years now --
why should we force them to change just because the
aesthetics seem better to people who have no stake in 
that code and work?

And FWIW, the key generation was discussed at long, long length
before last call. I doubt that Jeff remembers it, but he
was part of the discussion as I recall.

		Mike
signature.asc (application/pgp-signature, 307 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iQCVAwUAQf+shLMsDAj/Eq++AQLnOQP+Km5vqsn1ICf55MBKZZfKK8j7gorfkl/U
ZA7KnhQ/StATSoAokz3udKkSOsYyrWk5X35kecj7CW6uO1jzt+TPSm/pBB9DhD1J
6n3Ph/Fse0T+jHBjaYNGVwEFqCF9jSepr7v3zpZg1am49xAspFac/x/Qx00ovHZ3
tRwst17/rNo=
=r9go
-----END PGP SIGNATURE-----