[2263] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos DES <> MD5

daemon@ATHENA.MIT.EDU (Alan Crosswell)
Wed Oct 7 11:58:08 1992

Date: 7 Oct 92 13:59:57 GMT
From: alan@curta.cc.columbia.edu (Alan Crosswell)
To: kerberos@shelby.Stanford.EDU

In article <1992Oct7.112104.13517@nic.funet.fi> netmgr@tellus.csc.FI (Pekka  
Kytolaakso) writes:
> Are there any plans to make Kerberos V5 also use MD5 and not just DES.
> If i understand right MD5 has no export restrictions like DES.  Then you
> could make a kerberos_export.tar.Z that has the DES-part stripped out.
> 
> And example authentication library using MD5 and DES is in the
> latest version of xntp: ftp@louie.udel.edu:/pub/ntp/xntp3.tar.Z and
> ..../xntp3.export.tar.Z.
> 
> Pekka Kyt|laakso
> --
> ---------------------------------------------------------------
> netmgr@tellus.csc.fi     Centre for Scientific Computing
> Pekka.Kytolaakso@csc.fi  PL 40   SF-02101 Espoo FINLAND
> Phone: +358 0 4571       Telefax: + 358 0 4572302

I believe that MD5 is patented by RSADSI in the US of A.  It may be used
only under license from RSADSI in this country.  Due to the differences of
US vs. other countries' patent laws, RSADSI does not hold patents for
these same algorithms in most other countries of the world.  This has something
to do with the order in which the paper describing the algorithm and the
patent application are dated.  I believe the paper was published first, which
makes it unpatentable in many countries except the US.  So you can use it
for free in Finland but we can't here.  So instead of an export restriction
barrier, you hit a patent barrier.  Besides, any crypto technology is  
restricted from export.  So, an export license would be necessary for RSA
just as it is for DES and a Captain Midnite Decoder Ring.
/a

home help back first fref pref prev next nref lref last post