differences between des3-cbc-sha1 and des3-cbc-md5

Ahluwalia, Ish iahluwalia at sonusnet.com
Wed Sep 15 19:05:02 EDT 2004


Thanks Sam.  For a perosn who is new to encryption - What I understand from your statement below is that DES3-CBC-MD5 uses the regular checksum rsa-md5 and not rsa-md5-des3.  And, des3-cbc-md5 is not supported because rsa-md5 is an unkeyed hashing algorithm.  Is my understanding correct?

Thanks again.

Ish...  

-----Original Message-----
From: Sam Hartman [mailto:hartmans at mit.edu]
Sent: Tuesday, September 14, 2004 9:05 PM
To: Ahluwalia, Ish
Cc: kerberos at mit.edu
Subject: Re: differences between des3-cbc-sha1 and des3-cbc-md5


>>>>> "Ahluwalia," == Ahluwalia, Ish <iahluwalia at sonusnet.com> writes:

    Ahluwalia,> Essentially, I'm asking if if the process is same
    Ahluwalia,> between the two ciphersuites, just that HASH
    Ahluwalia,> algorithms are different?

No.  Completely different process.  I don't think des3-cbc-md5
supports doing anything with the keyusage etc.  This is one of the
many reasons it is not supported.

--Sam




More information about the Kerberos mailing list