Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There are no standard kerberos ciphersuites that use anything better than RC4/IDEA/DES/3DES: http://www.iana.org/assignments/tls-parameters/tls-parameter.... So: broken and obsolete.


Recent Windows, Linux and Java Kerberos all standardise on AES* and the ones you list are deprecated and for some have to be explicitly enabled.

So .. progress is being made.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: