[22415] in Kerberos
Re: Key derivation with non-ASCII characters
daemon@ATHENA.MIT.EDU (Ken Raeburn)
Thu Sep 9 12:12:55 2004
In-Reply-To: <a6732995.0409080514.25ee3d33@posting.google.com>
Mime-Version: 1.0 (Apple Message framework v619)
Content-Type: text/plain; charset=US-ASCII; format=flowed
Message-Id: <B05C9C37-0279-11D9-ABEA-000A95909EE2@mit.edu>
Content-Transfer-Encoding: 7bit
From: Ken Raeburn <raeburn@mit.edu>
Date: Thu, 9 Sep 2004 12:02:45 -0400
To: FrankSTaylor@gmail.com (Frank Taylor)
cc: kerberos@mit.edu
cc: Ken Raeburn <raeburn@mit.edu>
Errors-To: kerberos-bounces@mit.edu
On Sep 8, 2004, at 09:14, Frank Taylor wrote:
> The client code is jKrb5 (from
> http://www.mit.edu/afs/athena/astaff/project/krb5/raeburn/jkrb5 with a
> few fixes and additions).
Uh. I'm not used to people picking stuff up out of my random
development spaces, but okay... I picked that up a while ago, IIRC
it's related to the stonesoup java kerberos work. I have no idea if
it's current, if they're doing more work, if other people have bug
fixes, etc. My copy certainly shouldn't be considered an authoritative
source.
> 5) Summary
>
> It seems that our client code is correct w.r.t. to the draft Kerberos
> and crypto specs, however MS AD is producing/expecting different keys
> for non-7-bit-ASCII passwords even though the salt is the same.
>
> Any ideas on where to go next?
If no MS people answer promptly, I'd try a few other permutations.
Perhaps UTF-16 encodings for the password, or password and salt, for
the case where a non-ASCII character is found.
Ken
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos