Re: I-D Action: draft-ietf-krb-wg-des-die-die-die-02.txt
Tom Yu <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
Simon Josefsson <[email protected]> writes: > Any references to this vetting? Even RFC 4757 published 6 years ago > appears to me to say that the cipher SHOULD NOT be used for high-volume > connections, citing RC4 vulnerabilities as a reason. To me, this new > document implies RC4-HMAC is stronger than we thought it was before, > which seems surprising. I think RC4-HMAC is not stronger than we thought it was, and we should make sure this document doesn't make it seem that we are saying that. Perhaps if we say anything about RC4-HMAC, we should reiterate that the security considerations of RFC 4757 continue to apply, with the exception that RC4-HMAC-EXP is no longer considered secure. > The document title currently is "Deprecate DES support for Kerberos", so > yes, I suggest to remove the deprecation of RC4 from the document. If your concern is with the accuracy of the title, note that in this document, we already say an implementation SHOULD NOT implement some algorithms that do not involve DES -- CRC32 and RSA-MD4 among them. I'm not willing to drop all references to RC4-HMAC, because its continued safe (somewhat) usage in legacy deployments is a justification for allowing the limited use of RSA-MD5. _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg