[krbdev.mit.edu #1354] des3 string-to-key

Tom Yu via RT rt-comment at krbdev.mit.edu
Tue Feb 3 09:59:18 EST 2004


>>>>> "Ken" == Ken Raeburn via RT <rt-comment at krbdev.mit.edu> writes:

Ken> Our current string-to-key for des3 makes no checks or corrections
Ken> for weak keys.

[...]

Ken> The current crypto draft says we don't do weak-key checks, but
Ken> that's because I looked at our string-to-key and not the key
Ken> scheduling code.

Latest crypto draft says weak key checking is done.  We should update
the code.

---Tom



More information about the krb5-bugs mailing list