Kerberos v5

Posted on 2011-02-28
Medium Priority
Last Modified: 2012-05-11
Hi all,

just wondering what this qn means and whats the answer.

Many security tools/protocols/mechanisms, such as Kerberos V5, allow for more than one crypto-
graphic algorithm to take any particular role, such as encryption. Why do they do this, rather than
requiring the use of a particular algorithm, say AES, all the time?
Question by:moombaz
1 Comment
LVL 14

Accepted Solution

sjm_ee earned 2000 total points
ID: 35002374
For flexibility - encryption has been classed as military technology in certain countries at certain times and so supporting multiple options allows the framework to be used even if certain algorithms are restricted. It also allows users to switch algorithms in the future, for example if a major weakness is identified.


"Authorities in the United States classified Kerberos as auxiliary military technology and banned its export because it used the DES encryption algorithm (with 56-bit keys). A non-US Kerberos 4 implementation, KTH-KRB developed at the Royal Institute of Technology in Sweden, made the system available outside the US before the US changed its cryptography export regulations (circa 2000)."

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

In 2017, ransomware will become so virulent and widespread that if you aren’t a victim yourself, you will know someone who is.
Ransomware - Defeated! Client opened the wrong email and was attacked by Ransomware. I was able to use file recovery utilities to find shadow copies of the encrypted files and make a complete recovery.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question