@techreport{kaduk-afs3-rxkad-k5-kdf-00, number = {draft-kaduk-afs3-rxkad-k5-kdf-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-kaduk-afs3-rxkad-k5-kdf/00/}, author = {Benjamin Kaduk}, title = {{krb5 based key derivation for rxkad}}, pagetotal = 12, year = 2014, month = mar, day = 12, abstract = {This document describes two extensions to the rxkad security class for the RX RPC protocol, rxkad-k5 and rxkad-kdf. rxkad currently relies on the Kerberos Key Distribution Center to support single-DES encryption types, which are increasingly disabled by default in Kerberos implementations. This document provides a framework for rxkad to support long-term service keys with strong enctypes (rxkad-k5), and a key derivation procedure to allow Kerberos session keys with strong enctypes to be used with rxkad (rxkad-kdf).}, }