Re: I-D Action: draft-ietf-krb-wg-des-die-die-die-02.txt
Love Hörnquist Åstrand <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
13 feb 2012 kl. 07:49 skrev Tom Yu <[email protected]>: > Simon Josefsson <[email protected]> writes: > >> How about a title of "Deprecate historical algorithms in Kerberos" or >> something similar instead? Even though the document has contained >> references to RC4 before, I did not fully realize that before this >> discussion, because the title has caused me to treat this as >> DES-deprecation only. > > I prefer "Deprecate DES and other weak cryptographic algorithms in > Kerberos", because I think most of the problem consists of legacy > deployments I agree, let's deprecate des and rc4-hmac-exp. while rc4-hmac should also be deprecated, it's not horrible to use and for some deployments it's the only enctype available. If anything, msft should chime in and say what they think is the status of the rc4-hmac deployments, if they think its ready to be deprecated, it probably should. Love _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
smime.p7s
(application/pkcs7-signature, 2.5 KB) - not displayed