[22458] in Kerberos

home help back first fref pref prev next nref lref last post

Re: differences between des3-cbc-sha1 and des3-cbc-md5

daemon@ATHENA.MIT.EDU (Sam Hartman)
Wed Sep 15 20:52:38 2004

To: "Ahluwalia, Ish" <iahluwalia@sonusnet.com>
From: Sam Hartman <hartmans@mit.edu>
Date: Wed, 15 Sep 2004 20:50:10 -0400
In-Reply-To: <A3863F3136CBC546A40A61BA9CBA9D93ABD647@sonusmail03.sonusnet.com>
	(Ish Ahluwalia's message of "Wed, 15 Sep 2004 19:05:02 -0400")
Message-ID: <tslacvrca0t.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

>>>>> "Ahluwalia," == Ahluwalia, Ish <iahluwalia@sonusnet.com> writes:

    Ahluwalia,> Thanks Sam.  For a perosn who is new to encryption -
    Ahluwalia,> What I understand from your statement below is that
    Ahluwalia,> DES3-CBC-MD5 uses the regular checksum rsa-md5 and not
    Ahluwalia,> rsa-md5-des3.  And, des3-cbc-md5 is not supported
    Ahluwalia,> because rsa-md5 is an unkeyed hashing algorithm.  Is
    Ahluwalia,> my understanding correct?  Thanks again.  No.  That's
    not what I said at all.  All I said is that des3-cbc-md5 does not
    work the same way as des3-cbc-sha1.  One of the ways in which it
    does not work the same way is that it ignores the keyusage input
    to the crypto profile operations.

I have specifically made no positive statement about how it works; I
don't remember.  I remember some of the reasons it was not
standardized, that's all.

--Sam


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post