Re: [kitten] IANA number assignment for checksum type
Robbie Harwood <rharwood@redhat.com> Tue, 15 June 2021 16:45 UTC
Return-Path: <rharwood@redhat.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id 9C60A3A3623
for <kitten@ietfa.amsl.com>; Tue, 15 Jun 2021 09:45:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.795
X-Spam-Level:
X-Spam-Status: No, score=-2.795 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.698, DKIM_SIGNED=0.1,
DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001,
SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
header.d=redhat.com
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id QcdPOGSSN4A0 for <kitten@ietfa.amsl.com>;
Tue, 15 Jun 2021 09:45:41 -0700 (PDT)
Received: from us-smtp-delivery-124.mimecast.com
(us-smtp-delivery-124.mimecast.com [216.205.24.124])
(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id B8DDF3A3626
for <kitten@ietf.org>; Tue, 15 Jun 2021 09:45:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com;
s=mimecast20190719; t=1623775540;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:mime-version:mime-version:content-type:content-type:
in-reply-to:in-reply-to:references:references;
bh=BzhDmNFJXkIp9COLavguFn416MqYQJHkrMCspMAC4nU=;
b=UDZ907fkelXXYjKjMxQs80J5NFJ/u5oNigrrR5gjoOL+r/nnLuFIxtFgX9RTQH2kSdv8LX
Ln/tg51EPndXhZXDOEsNmuZ8k2diupPzov1atqMMm4gQx5Gj1eyNpKUrse+N9dRFGJQcGj
W72awpAKcBYnbKwmWg+NtIkyINck+Ag=
Received: from mail-qk1-f198.google.com (mail-qk1-f198.google.com
[209.85.222.198]) (Using TLS) by relay.mimecast.com with ESMTP id
us-mta-153-cM-JIx7WOUejfv8Cy1jnew-1; Tue, 15 Jun 2021 12:45:35 -0400
X-MC-Unique: cM-JIx7WOUejfv8Cy1jnew-1
Received: by mail-qk1-f198.google.com with SMTP id
v16-20020ae9e3100000b02903aafadba721so14150638qkf.6
for <kitten@ietf.org>; Tue, 15 Jun 2021 09:45:35 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20161025;
h=x-gm-message-state:from:to:subject:in-reply-to:references:date
:message-id:mime-version;
bh=bbp8Znbv5EFKsIUsTUYD+rQs+vPMcVNYe8w2zfpvB8U=;
b=K2pL/gKuGicVAQURHCmJsQkVM3rnYBWJ7BEek5DX5hzFqqLG+2/0WhOlJoNgSi3OFc
LLfq8q/Mg+BJDgQQvs4a570pxpb8vqzZerhBRC0RJwpncB0Qe5+fZ4qFXUBZB4agzzix
KKfLQB5gVwf9lrh2FrsFm5qmvF8SvkFDp/kPNMsRAtjXjg6BTy6rtnDYLVcXoh4BBZd0
MJCYijNUCi2I/ezOiz2llPgNRh4IhZFvIHLJr4OJ8ZC3DC6yYZpg41MaBtvyud3iGzfq
gf0SlP8ZD5YJauCYQbiFeztc7iYkTaFXr85gFCHWi63+MKt7cSBcxcyq6ZeZj6RWlxFZ
QwyA==
X-Gm-Message-State: AOAM531u+S3dRpDoBEZ0AR3emLfkBv/+KmXRGqiryCDPwZ01U41uEJAY
+g7Bj4MR1lYXuIYG0DTgN8GDag1oHjADdwPYrOCLp8GRd9986FFLq2B+Ehp9BEDiPx2DTfqq2k8
m5qCm9YU=
X-Received: by 2002:a37:aa50:: with SMTP id t77mr578078qke.102.1623775535396;
Tue, 15 Jun 2021 09:45:35 -0700 (PDT)
X-Google-Smtp-Source: ABdhPJyQsHJQ8hJ8Fr+8A4q3VaT35icjl/ZlXzO0/IxFY2LAvSeMIFe+6qNZKHnOszW0aiwe2+h9mA==
X-Received: by 2002:a37:aa50:: with SMTP id t77mr578063qke.102.1623775535149;
Tue, 15 Jun 2021 09:45:35 -0700 (PDT)
Received: from localhost (c-71-232-17-31.hsd1.ma.comcast.net. [71.232.17.31])
by smtp.gmail.com with ESMTPSA id
144sm12351312qkk.103.2021.06.15.09.45.33
(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
Tue, 15 Jun 2021 09:45:34 -0700 (PDT)
From: Robbie Harwood <rharwood@redhat.com>
To: Jishnu Renugopal <Jishnu.Renugopal@microsoft.com>, kitten@ietf.org
In-Reply-To: <MWHPR2101MB0809EB5EFF1989B9E1F1772295379@MWHPR2101MB0809.namprd21.prod.outlook.com>
References: <MWHPR2101MB0809EB5EFF1989B9E1F1772295379@MWHPR2101MB0809.namprd21.prod.outlook.com>
Date: Tue, 15 Jun 2021 12:45:33 -0400
Message-ID: <jlg4kdz9ivm.fsf@redhat.com>
MIME-Version: 1.0
Authentication-Results: relay.mimecast.com;
auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=rharwood@redhat.com
X-Mimecast-Spam-Score: 0
X-Mimecast-Originator: redhat.com
Content-Type: multipart/signed; boundary="=-=-=";
micalg=pgp-sha512; protocol="application/pgp-signature"
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/B1Md3jqoPt9hUp-_ks9hX2h3NQU>
Subject: Re: [kitten] IANA number assignment for checksum type
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>,
<mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>,
<mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jun 2021 16:45:47 -0000
Jishnu Renugopal <Jishnu.Renugopal=40microsoft.com@dmarc.ietf.org> writes: > Hi folks, > > We are working on adding new checksum types for the Windows > implementation of Kerberos namely – SHA256, SHA384, and SHA512 – all > unkeyed. > > We were wondering if we can get IANA assignments for these types here: > Kerberos Parameters > (iana.org)<https://www.iana.org/assignments/kerberos-parameters/kerberos-parameters.xhtml#kerberos-parameters-2>-2>. Hi, It sounds like you're adding support for RFC 8009 (AES Encryption with HMAC-SHA2 for Kerberos 5 - https://datatracker.ietf.org/doc/html/rfc8009 ) - is that right? That document defines aes128-cts-hmac-sha256-128 as 19 and hmac-sha384-192-aes256 as 20 (section 7). It looks like those are reflected in the registry you link (though it's possible that's been updated between your post and my reply). Thanks, --Robbie
- [kitten] IANA number assignment for checksum type Jishnu Renugopal
- Re: [kitten] IANA number assignment for checksum … Robbie Harwood
- Re: [kitten] [EXTERNAL] Re: IANA number assignmen… Jishnu Renugopal
- Re: [kitten] [EXTERNAL] Re: IANA number assignmen… Robbie Harwood