Re: des-die-die-die and RC4

Martin Rex <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
Tom Yu wrote:
> 
> Martin Rex wrote:
> >
> > The latter could be interpreted that RC4 is "export strength",
> > although the term "export strength" is not an attribute to RC4 in
> > general, but to variants of RC4 with a purposely short (or truncated) key.
> >
> > Not everyone is aware what "export strength" means.
> > With respect to RC4 export strength was originally 40(!) bit.
> 
> Right, because SSL originally had an exportable RC4 variant with
> 40-bit keys?  I guess the meaning of "export strength RC4" is clear in
> the context of Kerberos, but ambiguous with respect to RC4 in general.
> 
> I could change the title to "Deprecate DES, RC4-HMAC-EXP, and other
> weak cryptographic algorithms in Kerberos", along with a similar
> change to the Abstract.  I could also add some disambiguating text to
> other occurrences of "export strength" to emphasize that it's a
> variant of RC4 that has 56-bit keys.
 
Clarifying it _somehow_ in title an abstract would be
sufficient to make me happy.  I'm not addicted to any
specific fashion or term.   RC4-HMAC-EXP sounds good to me. 

-Martin

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.