Re: des-die-die-die and RC4
Simon Josefsson <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
Tom Yu <[email protected]> writes: > Simon Josefsson <[email protected]> writes: > >> I'm fine with deprecating RC4-EXP and not RC4 if the security >> considerations are modified to point at the security considerations of >> RFC 4757 instead of saying that RC4 is secure. > > Please let us know if the latest -03 revision text seems reasonable to > you. The security considerations seems fine now, thank you. I noticed another change in -03 though. Instead of saying that implementions and deployments SHOULD NOT "implement" the deprecated ciphers the document now says they SHOULD NOT "provide" them. What is the difference? It strikes me as "provide" is more ambigious than "implement". For example, is it OK to "provide" these ciphers as a non-default and still be compliant with the SHOULD NOT? The document didn't use to allow that. I don't recall any discussions around this change. Since we use SHOULD NOT instead of MUST NOT I believe we could use the harder language of "implement" instead of "provide". Implementations that wants to provide optional backwards compatibility can do so as an exception to the SHOULD NOT rule and still be compliant with the document. /Simon _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg