[OpenAFS] krb4 3des vulnerability

Chaskiel M Grundman cg2v@andrew.cmu.edu
Mon, 17 Mar 2003 19:36:35 -0500


--On Monday, March 17, 2003 18:53:43 -0500 Derek Atkins <warlord@MIT.EDU>
wrote:

> Knowing one is sufficient.

Unless I'm _really_ confused, knowing one is only sufficient for the 3des
vulnerability, which does not affect the kaserver. the single-des
vulnerability requires "many." I don't know how many "many" is, but I was
under the impression that, to an extent, they had to be choosable.