[3274] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

krb5-libs/1019: v4 has its own random number generator

daemon@ATHENA.MIT.EDU (hartmans@MIT.EDU)
Mon Nov 26 16:05:05 2001

Resent-From: gnats@rt-11.mit.edu (GNATS Management)
Resent-To: krb5-unassigned@rt-11.mit.edu
Resent-Reply-To: krb5-bugs@MIT.EDU, hartmans@MIT.EDU
Message-Id: <200111262104.QAA23325@tir-na-nogth.mit.edu>
Date: Mon, 26 Nov 2001 16:04:33 -0500 (EST)
From: hartmans@MIT.EDU
Reply-To: hartmans@MIT.EDU
To: krb5-bugs@mit.edu


>Number:         1019
>Category:       krb5-libs
>Synopsis:       v4 has its own random number generator
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    krb5-unassigned
>State:          open
>Class:          sw-bug
>Submitter-Id:   unknown
>Arrival-Date:   Mon Nov 26 16:05:00 EST 2001
>Last-Modified:
>Originator:     Sam Hartman
>Organization:
MIT
	
>Release:        1.2
>Environment:
	
System: SunOS tir-na-nogth.mit.edu 5.8 Generic_108528-08 sun4u sparc SUNW,Sun-Blade-100
Architecture: sun4

>Description:
The KDC code still calls des_init_random etc to use the krb4 RNG.
Perhaps  it should use the v5 RNG  even for v4 keys.

	
>How-To-Repeat:
	
>Fix:
	
>Audit-Trail:
>Unformatted:

krb4 has its own random number generator

home help back first fref pref prev next nref lref last post