RFC 6649: Deprecate DES, RC4-HMAC-EXP, and Other Weak Cryptographic Algorithms in Kerberos
In plain English — editorial summary, not part of the RFC
The Kerberos 5 network authentication protocol, originally specified in RFC 1510, can use the Data Encryption Standard (DES) for encryption. Almost 30 years after first publishing DES, the National Institute of Standards and Technology (NIST) finally withdrew the standard in 2005, reflecting a long-established consensus that DES is insufficiently secure. By 2008, commercial hardware costing less than USD 15,000 could break DES keys in less than a day on average. DES is long past its sell-by date. Accordingly, this document updates RFC 1964, RFC 4120, RFC 4121, and RFC 4757 to deprecate the use of DES, RC4-HMAC-EXP, and other weak cryptographic algorithms in Kerberos. Because RFC 1510 (obsoleted by RFC 4120) supports only DES, this document recommends the reclassification of RFC 1510 as Historic. This memo documents an Internet Best Current Practice.
Document record
- Document ID
- RFC6649
- Published
- July 2012
- Authors
- L. Hornquist Astrand; T. Yu
- Status
- BEST CURRENT PRACTICE
- Stream
- IETF
- Area
- sec
- Pages
- 7
- Also known as
- BCP179
- Obsoletes:
- RFC 1510
Standards lineage
This document is one revision in a chain of 3 RFCs, each formally replacing the one before it.
- RFC 1510 (1993)
- RFC 4120 (2005)
- RFC 6649 (2012)
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6664S/MIME Capabilities for Public Key DefinitionsCurrent
July 2012
- RFC 6630EAP Re-authentication Protocol Extensions for Authenticated Anticipatory Keying (ERP/AAK)Current
June 2012
- RFC 6677Channel-Binding Support for Extensible Authentication Protocol (EAP) MethodsCurrent
July 2012
- RFC 6678Requirements for a Tunnel-Based Extensible Authentication Protocol (EAP) MethodCurrent
July 2012
- RFC 6680Generic Security Service Application Programming Interface (GSS-API) Naming ExtensionsCurrent
August 2012
- RFC 6616A Simple Authentication and Security Layer (SASL) and Generic Security Service Application Program Interface (GSS-API) Mechanism for OpenIDCurrent
May 2012
- RFC 6614Transport Layer Security (TLS) Encryption for RADIUSUpdated
May 2012
- RFC 6684Guidelines and Template for Defining Extensions to the Incident Object Description Exchange Format (IODEF)Current
July 2012
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?