CurrentBEST CURRENT PRACTICEIETF streamBCP218

RFC 8429: Deprecate Triple-DES (3DES) and RC4 in Kerberos

In plain English — editorial summary, not part of the RFC

The triple-DES (3DES) and RC4 encryption types are steadily weakening in cryptographic strength, and the deprecation process should begin for their use in Kerberos. Accordingly, RFC 4757 has been moved to Historic status, as none of the encryption types it specifies should be used, and RFC 3961 has been updated to note the deprecation of the triple-DES encryption types. RFC 4120 is likewise updated to remove the recommendation to implement triple-DES encryption and checksum types.

Document record

Document ID
RFC8429
Published
October 2018
Authors
B. Kaduk; M. Short
Status
BEST CURRENT PRACTICE
Stream
IETF
Area
sec
Pages
10
Also known as
BCP218

Topics

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/8429-deprecate-triple-des-3des-and-rc4-in-kerberos