The RC4-HMAC Kerberos Encryption Types Used by Microsoft Windows
RFC 4757, “The RC4-HMAC Kerberos Encryption Types Used by Microsoft Windows”, is a Historic document published in December 2006 by K. Jaganathan, L. Zhu, J. Brezak. It has since been updated by RFC 6649. The canonical text is published by the RFC Editor.
Abstract
The Microsoft Windows 2000 implementation of Kerberos introduces a new encryption type based on the RC4 encryption algorithm and using an MD5 HMAC for checksum. This is offered as an alternative to using the existing DES-based encryption types.
The RC4-HMAC encryption types are used to ease upgrade of existing Windows NT environments, provide strong cryptography (128-bit key lengths), and provide exportable (meet United States government export restriction requirements) encryption. This document describes the implementation of those encryption types. This memo provides information for the Internet community.
What “Historic” means
A specification that has been superseded or is otherwise no longer recommended for use.
The canonical text of RFC 4757 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4756 Forward Error Correction Grouping Semantics in Session Description Protocol
- RFC 4758 Cryptographic Token Key Initialization Protocol Version 1.0 Revision 1
- RFC 4755 IP over InfiniBand: Connected Mode
- RFC 4759 The ENUM Dip Indicator Parameter for the "tel" URI
- RFC 4752 The Kerberos V5 Simple Authentication and Security Layer Mechanism
- RFC 4763 Extensible Authentication Protocol Method for Shared-secret Authentication and Key Establishment
- RFC 4750 OSPF Version 2 Management Information Base
- RFC 4749 RTP Payload Format for the G.729.1 Audio Codec