Re: I-D Action: draft-ietf-krb-wg-des-die-die-die-02.txt

Love Hörnquist Åstrand <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
13 feb 2012 kl. 07:49 skrev Tom Yu <[email protected]>:

> Simon Josefsson <[email protected]> writes:
> 
>> How about a title of "Deprecate historical algorithms in Kerberos" or
>> something similar instead?  Even though the document has contained
>> references to RC4 before, I did not fully realize that before this
>> discussion, because the title has caused me to treat this as
>> DES-deprecation only.
> 
> I prefer "Deprecate DES and other weak cryptographic algorithms in
> Kerberos", because I think most of the problem consists of legacy
> deployments 

I agree, let's deprecate des and rc4-hmac-exp. while rc4-hmac should also be deprecated, it's not horrible to use and for some deployments it's the only enctype available. If anything, msft should chime in and say what they think is the status of the rc4-hmac deployments, if they think its ready to be deprecated, it probably should.

Love

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
smime.p7s (application/pkcs7-signature, 2.5 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.