Re: CIFS and the krb5 PRF
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: CIFS and the krb5 PRF



On Jun 27, 2005, at 05:11, Andrew Bartlett wrote:
The 'CIFS Session key' export is just one of these required extensions -
we also need to change the GSS_Wrap arguments to support AEAD, and
closer control over the underlying Kerberos behaviour.

Hm, AEAD is needed for Samba? Wish I'd know that a year ago; it might've tipped the balance in favor of getting some sort of AEAD into RFC 3961. Can you point me to some additional info on this?


I don't think we can change GSS_Wrap to support AEAD without making it incompatible with previous specs. A new function would probably be needed.

Ken


_______________________________________________ Kitten mailing list Kitten at lists.ietf.org https://www1.ietf.org/mailman/listinfo/kitten




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.