Re: I-D Action: draft-ietf-krb-wg-des-die-die-die-02.txt

Tom Yu <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
Simon Josefsson <[email protected]> writes:

> Any references to this vetting?  Even RFC 4757 published 6 years ago
> appears to me to say that the cipher SHOULD NOT be used for high-volume
> connections, citing RC4 vulnerabilities as a reason.  To me, this new
> document implies RC4-HMAC is stronger than we thought it was before,
> which seems surprising.

I think RC4-HMAC is not stronger than we thought it was, and we should
make sure this document doesn't make it seem that we are saying that.
Perhaps if we say anything about RC4-HMAC, we should reiterate that
the security considerations of RFC 4757 continue to apply, with the
exception that RC4-HMAC-EXP is no longer considered secure.

> The document title currently is "Deprecate DES support for Kerberos", so
> yes, I suggest to remove the deprecation of RC4 from the document.

If your concern is with the accuracy of the title, note that in this
document, we already say an implementation SHOULD NOT implement some
algorithms that do not involve DES -- CRC32 and RSA-MD4 among them.

I'm not willing to drop all references to RC4-HMAC, because its
continued safe (somewhat) usage in legacy deployments is a
justification for allowing the limited use of RSA-MD5.
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.