[16317] in Kerberos_V5_Development
Re: wrong checksum type for arcfour-hmac-md5
daemon@ATHENA.MIT.EDU (Sam Hartman)
Thu Sep 16 16:29:18 2010
From: Sam Hartman <hartmans@mit.edu>
To: Greg Hudson <ghudson@mit.edu>
Date: Thu, 16 Sep 2010 16:28:52 -0400
In-Reply-To: <1284655172.5992.1737.camel@ray> (Greg Hudson's message of "Thu,
16 Sep 2010 12:39:32 -0400")
Message-ID: <tsl4odph1q3.fsf@live.mit.edu>
MIME-Version: 1.0
Cc: Luke Howard <lukeh@padl.com>, "krbdev@mit.edu Dev List" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
>>>>> "Greg" == Greg Hudson <ghudson@MIT.EDU> writes:
Greg> 2. Samba uses krb5_auth_con_set_req_cksumtype() to cause an
Greg> MD5 checksum to be used when the enctype is RC4.
Since there is not a security issue SAMBA could just use an md5 checksum
all the time.
I.E. a one-line fix independent of enctype.
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev