Re: Using SSPI to encrypt UDP messages



On Jan 29, 10:21 pm, "Eugene Mayevski" <mayev...@xxxxxxxxx> wrote:
Hello!
You wrote  on Tue, 29 Jan 2008 15:25:39 -0800 (PST):

 D> Take a look at RFC 1964 which defines the Kerberos V5 mechanism for
 D> GSS-API:http://www.ietf.org/rfc/rfc1964.txt

Hmm. Do I understand right, that you are offering a 10-year-old encryption
which uses outdated DES and MD5 as written in the RFC?

With best regards,
Eugene Mayevskihttp://www.SecureBlackbox.com- the comprehensive component suite for
network security

No, I was trying to provide links to information that show how an
authentication protocol can provide message encryption. The GSS-API
RFC is simply the framework on which Windows AuthN is built. See
http://www.rfc-archive.org/getrfc.php?rfc=4757 which documents the
Kerberos encryption mechanisms introduced in Windows 2000. The
algorithms used continue to evolve as the industry standards change.
Windows 2003 updated the algorithms further and Vista/Longhorn
supports the AES encryption suites and newer hash algs as well.

Dave
.



Relevant Pages

  • Re: Single Password - Linux & Windows
    ... an underlying m'soft mechanism is kerberos ... ... > be possible to deploy a kerberos configuration (across both windows ... > windows kerberos security tutorial ... > from my rfc index ...
    (linux.redhat)
  • Re: Single Password - Linux & Windows
    ... an underlying m'soft mechanism is kerberos ... ... > be possible to deploy a kerberos configuration (across both windows ... > windows kerberos security tutorial ... > from my rfc index ...
    (alt.os.linux.redhat)
  • Re: Single Password - Linux & Windows
    ... an underlying m'soft mechanism is kerberos ... ... > be possible to deploy a kerberos configuration (across both windows ... > windows kerberos security tutorial ... > from my rfc index ...
    (comp.os.linux.security)
  • Re: Really stupid question about z/OS HTTP server
    ... automagically logged on to their corresponding z/OS RACF id? ... IBM CICS RACF Security and Microsoft Windows Server 2003 Security ... kerberos was originally developed a MIT's Project Athena ...and then ... selecting RFC number brings up the corresponding summary in the lower ...
    (bit.listserv.ibm-main)
  • Re: Authentication architecture on a Unix Network
    ... recent post with LDAP reference ... now another widely used mechanism for authentication is Kerberos ... using digital signature for initial kerberos authentication mechanism ... for ietf RFC references ... ...
    (comp.security.unix)