[1037] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Revised 3-des gss proposal

daemon@ATHENA.MIT.EDU (Richard Basch)
Thu Mar 28 19:44:37 1996

Date: Thu, 28 Mar 1996 19:43:11 -0500
To: krbdev@MIT.EDU
From: "Richard Basch" <basch@lehman.com>


Because I have had problems implementing a 16 byte checksum for 3-des, I
propose that SGN_ALG 03 00 be:
	MD5-DES3MAC

Like the DES MAC case, the MD5 digest will have a cbc encrypt operation
(except in this case it is the 3-des cbc encrypt operation) done with a
zero ivec, and the last 64 bits will be used as the 8 byte checksum.

Btw, I have implemented the above form...

Richard Basch                   
Sr. Developer/Analyst           URL: http://web.mit.edu/basch/www/home.html
Lehman Brothers, Inc.           Email: basch@lehman.com, basch@mit.edu
101 Hudson St., 33rd Floor      Fax:   +1-201-524-5828
Jersey City, NJ 07302-3988      Voice: +1-201-524-5049


home help back first fref pref prev next nref lref last post