Re: I-D Action: draft-ietf-krb-wg-des-die-die-die-01.txt
Tom Yu <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
Simon Josefsson <[email protected]> writes: > Quick review of -01: > > The -01 document refers to 'RSA-MD4-MAC-K' instead of the RFC 3961 and > IANA name 'rsa-md4-des-k'. Thanks; I missed this somehow. Fixed in my copy. > There should be a reference to RFC 4757 when ARCFOUR-HMAC is mentioned, > and the reference should use the name RC4-HMAC instead of ARCFOUR-HMAC > since that is what RFC 4757 calls it. Implementations call it ARCFOUR-HMAC in various places for trademark reasons, as I recall. (Though skimming RFC 4757 reminds me that we might also want to deprecate rc4-hmac-exp (24) -- "export strength" RC4 -- as weak.) I'd be willing to skip that to get the document out sooner. Do people have strong opinions about naming it RC4 versus ARCFOUR? > In the same paragraph as ARCFOUR-HMAC is mentioned there is a reference > to "MIT's DES3" which eludes me, what does it refer to? As far as I > know, DES3 for Kerberos GSS-API is from IETF's RFC 3961 and RFC 4121. The details of using DES3 in Kerberos GSS-API in RFC 1964 token formats are not specified in an RFC, but MIT was first to implement it, and Heimdal also implements it. Notably, Microsoft does not implement DES3 Kerberos GSS-API tokens (or any Kerberos DES3 support at all). _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg