[22459] in Kerberos

home help back first fref pref prev next nref lref last post

RE: differences between des3-cbc-sha1 and des3-cbc-md5

daemon@ATHENA.MIT.EDU (Ahluwalia, Ish)
Thu Sep 16 11:42:10 2004

content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Date: Wed, 15 Sep 2004 19:05:02 -0400
Message-ID: <A3863F3136CBC546A40A61BA9CBA9D93ABD647@sonusmail03.sonusnet.com>
From: "Ahluwalia, Ish" <iahluwalia@sonusnet.com>
To: "Sam Hartman" <hartmans@mit.edu>
Content-Transfer-Encoding: 8bit
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

Thanks Sam.  For a perosn who is new to encryption - What I understand from your statement below is that DES3-CBC-MD5 uses the regular checksum rsa-md5 and not rsa-md5-des3.  And, des3-cbc-md5 is not supported because rsa-md5 is an unkeyed hashing algorithm.  Is my understanding correct?

Thanks again.

Ish...  

-----Original Message-----
From: Sam Hartman [mailto:hartmans@mit.edu]
Sent: Tuesday, September 14, 2004 9:05 PM
To: Ahluwalia, Ish
Cc: kerberos@mit.edu
Subject: Re: differences between des3-cbc-sha1 and des3-cbc-md5


>>>>> "Ahluwalia," == Ahluwalia, Ish <iahluwalia@sonusnet.com> writes:

    Ahluwalia,> Essentially, I'm asking if if the process is same
    Ahluwalia,> between the two ciphersuites, just that HASH
    Ahluwalia,> algorithms are different?

No.  Completely different process.  I don't think des3-cbc-md5
supports doing anything with the keyusage etc.  This is one of the
many reasons it is not supported.

--Sam


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post