Re: des-die-die-die and RC4

Simon Josefsson <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
Tom Yu <[email protected]> writes:

> Simon Josefsson <[email protected]> writes:
>
>> I'm fine with deprecating RC4-EXP and not RC4 if the security
>> considerations are modified to point at the security considerations of
>> RFC 4757 instead of saying that RC4 is secure.
>
> Please let us know if the latest -03 revision text seems reasonable to
> you.

The security considerations seems fine now, thank you.

I noticed another change in -03 though.  Instead of saying that
implementions and deployments SHOULD NOT "implement" the deprecated
ciphers the document now says they SHOULD NOT "provide" them.  What is
the difference?  It strikes me as "provide" is more ambigious than
"implement".  For example, is it OK to "provide" these ciphers as a
non-default and still be compliant with the SHOULD NOT?  The document
didn't use to allow that.  I don't recall any discussions around this
change.  Since we use SHOULD NOT instead of MUST NOT I believe we could
use the harder language of "implement" instead of "provide".
Implementations that wants to provide optional backwards compatibility
can do so as an exception to the SHOULD NOT rule and still be compliant
with the document.

/Simon
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.