Simple question on multiple mac/encryption algorithm

Sam Hartman hartmans at MIT.EDU
Mon Oct 20 11:37:25 EDT 2003


>>>>> "Gustavo" == Gustavo Rios <gustavo.rios at terra.com.br> writes:

    Gustavo> So it is not possible to combine n MAC vs. M ENC types in
    Gustavo> a upward compatible manner, right ?


Your question is not even well-formed for Kerberos. It's not generally
possible, for many reasons.  Consider for example an enctype that
provides its own integrity protection such as the authenticated
encryption modes being discussed in the IRTF and other cryptography
circles.




More information about the Kerberos mailing list