Re: I-D Action: draft-ietf-krb-wg-des-die-die-die-02.txt

Simon Josefsson <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
Tom Yu <[email protected]> writes:

> Simon Josefsson <[email protected]> writes:
>
>> Tom Yu <[email protected]> writes:
>>
>>> Changes since -01:
>>>
>>> Deprecate "export strength" RC4-HMAC-EXP.  This requires a normative
>>> downref to RFC 4757 (though a trivial one because its purpose is to
>>> deprecate part of the downref).
>>
>> To me, deprecating RC4-HMAC-EXP but not RC4-HMAC implies that we regard
>> non-export strength RC4-HMAC as secure.  I think this is unfortunate.
>
> We already address RC4-HMAC in the Security Considerations.

That section reads:

   RC4, used in RC4-HMAC, is considered weak; however, the use in
   Kerberos is vetted and considered secure for now.

Any references to this vetting?  Even RFC 4757 published 6 years ago
appears to me to say that the cipher SHOULD NOT be used for high-volume
connections, citing RC4 vulnerabilities as a reason.  To me, this new
document implies RC4-HMAC is stronger than we thought it was before,
which seems surprising.

> Keep in mind that RFC 4757 is Informational, so a standards-conforming
> implementation isn't required to do anything with it anyway.

That is why I propose that this document does not discuss RC4 at all.

>> I'd prefer that we deprecated both RC4-HMAC and RC4-HMAC-EXP.  Second to
>> that, that we say nothing at all about RFC 4757 and let readers pass
>> their own judgement on it.
>
> There's been text in the Security Considerations about RC4-HMAC since
> before my edits.  The document simply neglected to cite RFC 4757
> previously.  Are you suggesting that we remove the preexisting text
> from the Security Considerations?  Also, RFC 4757 itself recommends
> not using RC4-HMAC if stronger enctypes are available.

The document title currently is "Deprecate DES support for Kerberos", so
yes, I suggest to remove the deprecation of RC4 from the document.

/Simon
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.