arcfour-hmac checksum salt value

Marcus Watts mdw at
Tue Mar 11 14:28:47 EDT 2008

> Date:    Tue, 11 Mar 2008 12:42:52 EDT
> To:      "Kerberos developers list" <krbdev at>,
> 	 "Heimdal-discuss list" <heimdal-discuss at>
> From:    "Kevin Coffman" <kwc at>
> Subject: arcfour-hmac checksum salt value
> While implementing arcfour-hmac for Linux Kernel NFS use, I have run
> into the following issue:
> According to rfc4757 (sections 7.2 and 7.3), the salt value when
> generating the checksum for both MIC and WRAP tokens is 15.  However,
> the MIT, Heimdal, and Java implementations all seem to map the usage
> values (used while creating the checksum) in WRAP tokens to a salt
> value of 13 instead.
> Can someone verify that either I'm confused, or the spec is wrong in
> the case of the checksum salt value that Microsoft used for WRAP
> tokens?
> Thanks,
> K.C.

Perhaps they meant to specify it in octal?

				-Marcus Watts

More information about the krbdev mailing list