[22435] in Kerberos
Re: Use of Encryption for KRB_AP_REQ
daemon@ATHENA.MIT.EDU (Sam Hartman)
Sat Sep 11 12:40:23 2004
To: "Ahluwalia, Ish" <iahluwalia@sonusnet.com>
From: Sam Hartman <hartmans@mit.edu>
Date: Sat, 11 Sep 2004 12:38:27 -0400
In-Reply-To: <A3863F3136CBC546A40A61BA9CBA9D93ABD63B@sonusmail03.sonusnet.com>
(Ish Ahluwalia's message of "Fri, 10 Sep 2004 19:43:08 -0400")
Message-ID: <tslacvwyd4s.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
>>>>> "Ahluwalia," == Ahluwalia, Ish <iahluwalia@sonusnet.com> writes:
Ahluwalia,> Hi All: I'm new to kerberos world, so appologies in
Ahluwalia,> advance if it's too basic of a question. Does MIT
Ahluwalia,> kerberos support des3-cbc-md5 encryption type? I have
Ahluwalia,> a requirement which requires me to have the
Ahluwalia,> Authenticator field of the AP_REQ to be encrypted
Ahluwalia,> using 3des-cbc-md5 encryption algorithm. Looking at
Ahluwalia,> krb5.h file and the IETF specification, it doesn't
Ahluwalia,> look like this algorithm is supported. Any help will
Ahluwalia,> be greatly appreciated? Is there a way to get around
Ahluwalia,> this problem and still use MIT kerberos V5.
No, MIT Kerberos does not support this algorithm. It was a
nonstandard hack that we supported for one release inside a #ifdef 0
block. It has not received significant security review and will not
be standardized.
Sam Hartman
MIT Information Services and Technology
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos