Internet Engineering Task Force (IETF) L. Hornquist Astrand Request for Comments: 6649 Apple, Inc. BCP: 179 T. Yu Obsoletes: 1510 MIT Kerberos Consortium Updates: 1964, 4120, 4121, 4757 July 2012 Category: Best Current Practice ISSN: 2070-1721Deprecate DES, RC4-HMAC-EXP, and Other Weak Cryptographic Algorithms in Kerberos
Hornquist Astrand & Yu Best Current Practice [Page 1]
RFC 6649 Deprecate DES in Kerberos July 2012
Copyright Notice
Hornquist Astrand & Yu Best Current Practice [Page 2]
RFC 6649 Deprecate DES in Kerberos July 2012 1. IntroductionThe original specification of the Kerberos 5 network authentication protocol [RFC1510] supports only the Data Encryption Standard (DES) for encryption. For many years, the cryptographic community has regarded DES as providing inadequate security, mostly because of its small key size. Accordingly, this document recommends the reclassification of [RFC1510] (obsoleted by [RFC4120]) as Historic and updates current Kerberos-related specifications [RFC1964], [RFC4120], and [RFC4121] to deprecate the use of DES and other weak cryptographic algorithms in Kerberos, including some unkeyed checksums and hashes, along with the weak 56-bit "export strength" RC4 variant encryption type of [RFC4757].
2. Requirements Notation
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].
3. Affected Specifications
The original IETF specification of Kerberos 5 [RFC1510] only supports DES for encryption. [RFC4120] obsoletes [RFC1510] and updates the Kerberos specification to include additional cryptographic algorithms, but still permits the use of DES. [RFC3961] describes the Kerberos cryptographic system and includes support for DES encryption types, but it does not specify requirement levels for them.
Hornquist Astrand & Yu Best Current Practice [Page 3]
RFC 6649 Deprecate DES in Kerberos July 2012 4. DES InsecurityThe insecurity of DES has been evident for many years. Even around the time of its first publication, cryptographers raised the possibility that 56 bits was too small a key size for DES. The National Institute of Standards and Technology (NIST) officially withdrew DES in 2005 [DES-Withdrawal], and also announced a transition period that ended on May 19, 2007 [DES-Transition-Plan]. The IETF has also published its position in [RFC4772], in which the recommendation summary is very clear: "don't use DES".
5. Recommendations
This document hereby removes the following RECOMMENDED types from [RFC4120]:
Hornquist Astrand & Yu Best Current Practice [Page 4]
RFC 6649 Deprecate DES in Kerberos July 2012
Kerberos GSS mechanism implementations and deployments SHOULD NOT implement or deploy the following SGN ALG: DES MAC MD5(0000), MD2.5(0100), DES MAC(0200) (updates [RFC1964]).
6. Security Considerations
Removing support for single DES improves security because DES is considered to be insecure. RC4-HMAC-EXP has a similarly inadequate key size, so removing support for it also improves security.
7. Acknowledgements
Mattias Amnefelt, Ran Atkinson, Henry Hotz, Jeffrey Hutzelman, Leif Johansson, Simon Josefsson, and Martin Rex have read the document and provided suggestions for improvements. Sam Hartman proposed moving [RFC1510] to Historic. Michiko Short provided information about the dates of end of support for Windows releases.
Hornquist Astrand & Yu Best Current Practice [Page 5]
RFC 6649 Deprecate DES in Kerberos July 2012 8. References 8.1. Normative References[RFC1964] Linn, J., "The Kerberos Version 5 GSS-API Mechanism",
8.2. Informative References
[Break-DES] Kumar, S., Paar, C., Pelzl, J., Pfeiffer, G., Rupp, A.,
Hornquist Astrand & Yu Best Current Practice [Page 6]
RFC 6649 Deprecate DES in Kerberos July 2012
[DES-Withdrawal]