Solved

Kerberos v5

Posted on 2011-02-28
1
748 Views
Last Modified: 2012-05-11
Hi all,

just wondering what this qn means and whats the answer.

Many security tools/protocols/mechanisms, such as Kerberos V5, allow for more than one crypto-
graphic algorithm to take any particular role, such as encryption. Why do they do this, rather than
requiring the use of a particular algorithm, say AES, all the time?
0
Comment
Question by:moombaz
1 Comment
 
LVL 14

Accepted Solution

by:
sjm_ee earned 500 total points
ID: 35002374
For flexibility - encryption has been classed as military technology in certain countries at certain times and so supporting multiple options allows the framework to be used even if certain algorithms are restricted. It also allows users to switch algorithms in the future, for example if a major weakness is identified.

http://en.wikipedia.org/wiki/Kerberos_%28protocol%29

"Authorities in the United States classified Kerberos as auxiliary military technology and banned its export because it used the DES encryption algorithm (with 56-bit keys). A non-US Kerberos 4 implementation, KTH-KRB developed at the Royal Institute of Technology in Sweden, made the system available outside the US before the US changed its cryptography export regulations (circa 2000)."
0

Featured Post

Live: Real-Time Solutions, Start Here

Receive instant 1:1 support from technology experts, using our real-time conversation and whiteboard interface. Your first 5 minutes are always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
Worried about if Apple can protect your documents, photos, and everything else that gets stored in iCloud? Read on to find out what Apple really uses to make things secure.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question