[4114] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

[krbdev.mit.edu #1429] AES/GSS combination broken

daemon@ATHENA.MIT.EDU (Ken Raeburn via RT)
Fri Apr 18 01:47:31 2003

Date: Fri, 18 Apr 2003 01:47:23 -0400 (EDT)
Message-Id: <rt-1429-5769.8.43937602806321@krbdev.mit.edu>
In-Reply-To: <rt-1429@krbdev.mit.edu>
From: "Ken Raeburn via RT" <rt-comment@krbdev.mit.edu>
To: krb5-prs@mit.edu
Reply-To: rt-comment@krbdev.mit.edu
Errors-To: krb5-bugs-bounces@mit.edu


Our GSS krb5 mechanism code limits the enctypes used to those
supported by GSS before trying to acquire the service ticket.  With
the AES support in the krb5 library checked in, and no support in the
GSS mechanism for it, this means a TGT with an AES session key cannot
be used to get a service ticket with a 3DES or DES session key.

I'll bring this up on the krbdev list for discussion.

In theory, the test suite should probably be limiting the ftp or host
service to the key types supported by the GSS implementation used for
the server, in case the client-supported list is different, but since
we're only really testing the same version of client and server code
at one time, and we've tended to add the support simultaneously, it's
not a priority.
_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
http://mailman.mit.edu/mailman/listinfo/krb5-bugs

home help back first fref pref prev next nref lref last post