The Unencrypted Form of Kerberos 5 KRB-CRED Message
RFC 6448

(Jari Arkko) No Objection

(David Harrington) No Objection

"can been" -> "has been" or "can be"

(Russ Housley) No Objection

Please consider the editorial comments in the Gen-ART Review by
  Kathleen Moriarty on 24-Aug-2011.

This document does describe how to do something (albeit unsavory) in an interoperable manner, and I can imagine this document being refined with experience, so it is at least plausible to leave on the standards track. And the document does have serious admonitions about how this protocol ought to be used. I share Dave's discomfort, but I think this document has an acceptable level of warning to implementers.

1. I share the feeling of uneasiness expressed by DBH about putting this document on the standards track. I expect the security experts to ease my concerns. 

2. In the IANA considerations section: 

 The reference for Kerberos encryption type 0 should be updated to
   point to this document.

It would be probably good to mention that this is the Kerberos Encryption Type Numbers in the Kerberos parameters registry. Should not it also say something like 'message not encrypted' instead of 'reserved'? 

It would be nice if this document included a sentence or two about why the KRB-CRED Message was removed between RFC 1510 and RFC 4510, and why it's important to bring that feature back now. As it is, that history is hidden in the mail archive, so it appears to the naive reader that the KRB-CRED Message is a new feature.

