Re: Password Salting Methods

2008-06-01 Thread Michael B Allen
On 6/2/08, Ken Raeburn <[EMAIL PROTECTED]> wrote: > On May 29, 2008, at 22:22, Michael B Allen wrote: > > > Is there a reference anywhere that outlines the different password > > salting methods used by different KDCs? > > > > There are RFCs 3961, 3962, and

Re: Password Salting Methods

2008-06-01 Thread Ken Raeburn
On May 29, 2008, at 22:22, Michael B Allen wrote: > Is there a reference anywhere that outlines the different password > salting methods used by different KDCs? There are RFCs 3961, 3962, and 4757, which outline how salt strings are incorporated in the string-to-key conversion function fo

Password Salting Methods

2008-05-30 Thread Michael B Allen
Hi, Is there a reference anywhere that outlines the different password salting methods used by different KDCs? AFAICT AD w/ RC4 doesn't actually use a salt. Heimdal seems to just use the realm and principal name concatenated together without any separators. What does MIT do? What does Wi