Re: des-die-die-die and RC4
Thomas Maslen <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <D5847DD823005F4E9DB94FE77DCEDF680FFB27B0@ALVMBXW01.prod.quest.corp> |
> My read is that the rough consensus of the working group is that > deprecating RC4 at this time is not desirable. I too am in favour of "at this time, don't deprecate RC4". > [...] comments on whether people want to deprecate rc4-exp I don't have a strong preference, but I am mildly in favour of deprecating rc4-hmac-exp. Part of the reason I say that is: Back in about 2005 I got someone to implement it, because I was worried that we might need to handle it (e.g. maybe from old versions of Internet Explorer that didn't have the better encryption pack added). We never got around to actually shipping it in our product, because we have never run into a case where we needed it; in the seven years since then I don't think we've ever seen it in the wild. In other words, from my (admittedly very skewed) sample, it isn't in widespread use, so deprecating it won't hurt too many people (anyone?), and of course _not_ deprecating it may hurt security. _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg