2 Aug 2009 12:00
I-D Action:draft-lha-des-die-die-die-01.txt
<Internet-Drafts <at> ietf.org>
2009-08-02 10:00:01 GMT
2009-08-02 10:00:01 GMT
A New Internet-Draft is available from the on-line Internet-Drafts directories. Title : Deprecate DES support for Kerberos Author(s) : L. Astrand Filename : draft-lha-des-die-die-die-01.txt Pages : 10 Date : 2009-08-02 A long long time ago DES was standardized. Some 30 years later (2003) is was withdrawn as a standard by NIST, today 6 years later, its time for DES to finally die. By 2008 it was possible to brute force DES keys in 6.4 days using less than USD 10k worth of hardware. So by 2008 DES had passed its sell-by date. Use in Kerberos should therefore stop.1. Requirements Notation The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].2. Background Kerberos 5 was defined in [RFC1510] and updated in [RFC4120], the Kerberos crypto system is defined by [RFC3961] and includes support for DES encryption types. This document move all of the DES encryption and related checksum types to historic. DES was withdrawn in [DES-Transition-Plan] by NIST. IETF have also published its the position in [RFC4772], which in the recommendation summery is made very clear: "don't use DES".3. Recommendations This document removes the mandatory-to-implement types from [RFC4120]: Encryption: DES-CBC-MD5(Continue reading)
RSS Feed