#28 [*] Key usage
Kazunori Miyazawa <[email protected]> Tue, 08 Feb 2005 13:38:04 +0900
| Newsgroups | gmane.ietf.kink |
|---|---|
| Message-ID | <[email protected]> |
Hello, I considered the issue and got questions. The issue is #28 [*] Key usage Usage of kink should specify the key usage numbers for kerberos encryption. If KINK uses kcrypto, we can find key usage numbers in draft-ietf-krb-wg-kerberos-clarificaiton. However in section 4 of the clarifications There might exist other documents which define protocols in terms of the RFC1510 encryption types or checksum types. Such documents would not know about key usages. In order that these specifications continue to be meaningful until they are updated, if no key usage values are specified then key usages 1024 and 1025 must be used to derive keys for encryption and checksums, respectively (this does not apply to protocols that do their own encryption independent of this framework, directly using the key resulting from the Kerberos authentication exchange.) New protocols defined in terms of the Kerberos encryption and checksum types SHOULD use their own key usage values. The questions are: 1. Does KINK correspond to whether protocol in terms of the RFC1510 or new protocol? 2. If KINK is protocol in terms of the RFC1510, is KINK able to use 1024 and 1025? 3. Otherwise, I think we should assign the numbers. How will we assign the numbers? Does it raise IANA issue? -- Kazunori Miyazawa