Deprecate Triple-DES and RC4 in Kerberos
RFC 8429, “Deprecate Triple-DES and RC4 in Kerberos”, is a Best Current Practice document published in October 2018 by B. Kaduk, M. Short. It updates RFC 3961, RFC 4120. The canonical text is published by the RFC Editor.
Abstract
The triple-DES (3DES) and RC4 encryption types are steadily weakening in cryptographic strength, and the deprecation process should begin for their use in Kerberos. Accordingly, RFC 4757 has been moved to Historic status, as none of the encryption types it specifies should be used, and RFC 3961 has been updated to note the deprecation of the triple-DES encryption types. RFC 4120 is likewise updated to remove the recommendation to implement triple-DES encryption and checksum types.
What “Best Current Practice” means
Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.
The canonical text of RFC 8429 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8428 Sensor Measurement Lists
- RFC 8430 RIB Information Model
- RFC 8427 Representing DNS Messages in JSON
- RFC 8431 A YANG Data Model for the Routing Information Base
- RFC 8426 Recommendations for RSVP-TE and Segment Routing Label Switched Path Coexistence
- RFC 8432 A Framework for Management and Control of Microwave and Millimeter Wave Interface Parameters
- RFC 8425 IANA Considerations for IPv6 Neighbor Discovery Prefix Information Option Flags
- RFC 8433 A Simpler Method for Resolving Alert-Info URNs