Re: Subsession keys (Re: KINK issue list)
Michael Thomas <[email protected]> Tue, 01 Feb 2005 08:21:24 -0800
| Newsgroups | gmane.ietf.kink |
|---|---|
| Organization | Cisco Systems |
| Message-ID | <[email protected]> |
On Mon, 2005-01-31 at 17:41, Sam Hartman wrote: > >>>>> "Michael" == Michael Thomas <[email protected]> writes: > My reason for bringing up the issue is that you are behaving > differently than all other Kerberos applications. Kerberos libraries > are actually flexible enough to do what your spec currently asks but > it requires implementers to specifically handle subkeys that way. > > If you don't have a reason for being different then please be the same > as everyone else. If you do have a reason, explain it and I'll be > happy. I'm sorry, but I'm having a real problem with this guilty until proven innocent stance. This document was through several iterations of review from the IESG and just got dropped on the floor by the IESG. I think it's incumbent on those who are throwing darts here to say if there are REAL PROBLEMS, not just harmonization with the universe. In this particular case, I had *zero* problem coding this up. Is there an _actual_ cryptographical problem here, or is this another trip to the beauty shop? There are people who have been writing to *this* spec for several years now -- why should we force them to change just because the aesthetics seem better to people who have no stake in that code and work? And FWIW, the key generation was discussed at long, long length before last call. I doubt that Jeff remembers it, but he was part of the discussion as I recall. Mike
signature.asc
(application/pgp-signature, 307 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iQCVAwUAQf+shLMsDAj/Eq++AQLnOQP+Km5vqsn1ICf55MBKZZfKK8j7gorfkl/U ZA7KnhQ/StATSoAokz3udKkSOsYyrWk5X35kecj7CW6uO1jzt+TPSm/pBB9DhD1J 6n3Ph/Fse0T+jHBjaYNGVwEFqCF9jSepr7v3zpZg1am49xAspFac/x/Qx00ovHZ3 tRwst17/rNo= =r9go -----END PGP SIGNATURE-----