[22342] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Key derivation with non-ASCII characters

daemon@ATHENA.MIT.EDU (Frank Taylor)
Wed Sep 1 13:09:44 2004

From: FrankSTaylor@gmail.com (Frank Taylor)
Date: 1 Sep 2004 07:20:00 -0700
Message-ID: <a6732995.0409010620.32ca24f1@posting.google.com>
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

> No, although an explanation of why the problem is hard and why in
> general you may not be able to solve it is in
> draft-ietf-krb-wg-kerberos-clarifications (successor to RFC 1510).

Thanks for the pointer... I have now found: Encryption and Checksum
Specifications for Kerberos 5 (draft-ietf-krb-wg-crypto-07.txt). I
like the way the standard was changed to agree with the
implementations of DES string-to-key rather than the other way around!

> Microsoft will expect you to encode things as UTF8.  I don't know what
> your implementation actually does.

The clarified draft explicitly states that the input strings (password
and salt) to string-to-key must be in  UTF-8.

I have updated my string-to-key function to use UTF-8, but it still
does not generate the same keys as MS AD is expecting. Something else
must be going on. A different algorithm for passwords with
non-7-bit-ASCII characters (horrible!)?

The search continues...

Frank.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post