[22435] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Use of Encryption for KRB_AP_REQ

daemon@ATHENA.MIT.EDU (Sam Hartman)
Sat Sep 11 12:40:23 2004

To: "Ahluwalia, Ish" <iahluwalia@sonusnet.com>
From: Sam Hartman <hartmans@mit.edu>
Date: Sat, 11 Sep 2004 12:38:27 -0400
In-Reply-To: <A3863F3136CBC546A40A61BA9CBA9D93ABD63B@sonusmail03.sonusnet.com>
	(Ish Ahluwalia's message of "Fri, 10 Sep 2004 19:43:08 -0400")
Message-ID: <tslacvwyd4s.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

>>>>> "Ahluwalia," == Ahluwalia, Ish <iahluwalia@sonusnet.com> writes:

    Ahluwalia,> Hi All: I'm new to kerberos world, so appologies in
    Ahluwalia,> advance if it's too basic of a question.  Does MIT
    Ahluwalia,> kerberos support des3-cbc-md5 encryption type?  I have
    Ahluwalia,> a requirement which requires me to have the
    Ahluwalia,> Authenticator field of the AP_REQ to be encrypted
    Ahluwalia,> using 3des-cbc-md5 encryption algorithm.  Looking at
    Ahluwalia,> krb5.h file and the IETF specification, it doesn't
    Ahluwalia,> look like this algorithm is supported.  Any help will
    Ahluwalia,> be greatly appreciated?  Is there a way to get around
    Ahluwalia,> this problem and still use MIT kerberos V5.

No, MIT Kerberos does not support this algorithm.  It was a
nonstandard hack that we supported for one release inside a #ifdef 0
block.  It has not received significant security review and will not
be standardized.

Sam Hartman
MIT Information Services and Technology

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post