Re: A thought on 40-bit DES keys
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: A thought on 40-bit DES keys



"John Gardiner Myers" <jgmyers at netscape.com> writes:

> A thought occured to me that draft-hoffman-des40 may be useful in an IETF
> standard.  It may be a good idea to revise the Kerberos V5 specification to
> state that keys conforming to draft-hoffman-des40 MUST NOT be used in the
> des-* enctypes, just like keys which are "weak" or "semiweak" per the DES
> specification shall not be used.
> 
> That way, a host with a policy of using 56 bits will not be fooled into
> communicating with an implementation with an incompatible policy.

56bit DES is already weak, why spent more cycles perfecting Kerberos V5's use
it? I'd rather see energy spent on 3DES for Kerberos V5.

	-mre



Note Well: Messages sent to this mailing list are the opinions of the senders and do not imply endorsement by the IETF.

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.