[4106] in Kerberos-V5-bugs
[krbdev.mit.edu #1415] subkeys fubar
daemon@ATHENA.MIT.EDU (Public Submitter via RT)
Thu Apr 17 11:58:08 2003
Date: Thu, 17 Apr 2003 11:57:53 -0400 (EDT)
Mail-Followup-To: rt@krbdev.mit.edu
Message-Id: <rt-1415-5761.6.66517823184165@krbdev.mit.edu>
In-Reply-To: <rt-1415@krbdev.mit.edu>
From: "Public Submitter via RT" <rt-comment@krbdev.mit.edu>
Mail-Copies-To: never
To: tlyu@MIT.EDU
cc: krb5-prs@MIT.EDU
Reply-To: rt-comment@krbdev.mit.edu
Errors-To: krb5-bugs-bounces@mit.edu
[tlyu - Wed Apr 16 19:40:57 2003]:
> Do we want an option to allow for "server subkey wins"?
RFC1510 and clarifications pretty much leave subkey negotiation to the
applications.
To stay true to this the APIs could allow an application-provided
callback function
to produce the local and remote sub-keys given the proposed sub-keys
from the
AP exchange as input.
> Are there any applications currently depending on the functionality of
> unidirectional subsession keys?
Er, well, I suspect not, but if the default mkr_req/mk_rep behaviour
changes apps
would break, no? What about older kcmd? Is there a reflection attack
there if
unidirectional keys are not used?
Nico
_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
http://mailman.mit.edu/mailman/listinfo/krb5-bugs