Re: I-D Action: draft-ietf-krb-wg-des-die-die-die-02.txt
Simo Sorce <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Organization | Red Hat, Inc. |
| Message-ID | <[email protected]> |
On Mon, 2012-02-13 at 14:42 +0100, Simon Josefsson wrote: > Tom Yu <[email protected]> writes: > > > Simon Josefsson <[email protected]> writes: > > > >> Any references to this vetting? Even RFC 4757 published 6 years ago > >> appears to me to say that the cipher SHOULD NOT be used for high-volume > >> connections, citing RC4 vulnerabilities as a reason. To me, this new > >> document implies RC4-HMAC is stronger than we thought it was before, > >> which seems surprising. > > > > I think RC4-HMAC is not stronger than we thought it was, and we should > > make sure this document doesn't make it seem that we are saying that. > > Perhaps if we say anything about RC4-HMAC, we should reiterate that > > the security considerations of RFC 4757 continue to apply, with the > > exception that RC4-HMAC-EXP is no longer considered secure. > > That seems like a good idea. > > >> The document title currently is "Deprecate DES support for Kerberos", so > >> yes, I suggest to remove the deprecation of RC4 from the document. > > > > If your concern is with the accuracy of the title, note that in this > > document, we already say an implementation SHOULD NOT implement some > > algorithms that do not involve DES -- CRC32 and RSA-MD4 among them. > > How about a title of "Deprecate historical algorithms in Kerberos" or > something similar instead? Even though the document has contained > references to RC4 before, I did not fully realize that before this > discussion, because the title has caused me to treat this as > DES-deprecation only. I am for narrowing the scope to DES and getting this standard out ASAP. It has been bounced enough, and adding more discussion to deprecate other algorithms would only delay it, further. Meanwhile DES is really insecure these days and we ought to deprecate it officially so that all vendors wake up and start moving off of it for real. Simo. -- Simo Sorce * Red Hat, Inc * New York _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg