Deprecate DES, RC4-HMAC-EXP, and Other Weak Cryptographic Algorithms in Kerberos
RFC 6649, “Deprecate DES, RC4-HMAC-EXP, and Other Weak Cryptographic Algorithms in Kerberos”, is a Best Current Practice document published in July 2012 by L. Hornquist Astrand, T. Yu. It updates RFC 1964, RFC 4120, RFC 4121, RFC 4757. It obsoletes RFC 1510. The canonical text is published by the RFC Editor.
Abstract
The Kerberos 5 network authentication protocol, originally specified in RFC 1510, can use the Data Encryption Standard (DES) for encryption. Almost 30 years after first publishing DES, the National Institute of Standards and Technology (NIST) finally withdrew the standard in 2005, reflecting a long-established consensus that DES is insufficiently secure. By 2008, commercial hardware costing less than USD 15,000 could break DES keys in less than a day on average. DES is long past its sell-by date. Accordingly, this document updates RFC 1964, RFC 4120, RFC 4121, and RFC 4757 to deprecate the use of DES, RC4-HMAC-EXP, and other weak cryptographic algorithms in Kerberos. Because RFC 1510 (obsoleted by RFC 4120) supports only DES, this document recommends the reclassification of RFC 1510 as Historic. This memo documents an Internet Best Current Practice.
What “Best Current Practice” means
Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.
The canonical text of RFC 6649 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6648 Deprecating the "X-" Prefix and Similar Constructs in Application Protocols
- RFC 6650 Creation and Use of Email Feedback Reports: An Applicability Statement for the Abuse Reporting Format
- RFC 6647 Email Greylisting: An Applicability Statement for SMTP
- RFC 6651 Extensions to DomainKeys Identified Mail for Failure Reporting
- RFC 6646 DECoupled Application Data Enroute Problem Statement
- RFC 6652 Sender Policy Framework Authentication Failure Reporting Using the Abuse Reporting Format
- RFC 6645 IP Flow Information Accounting and Export Benchmarking Methodology
- RFC 6653 DHCPv6 Prefix Delegation in Long-Term Evolution Networks