[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Last Call: 'Kerberized Internet Negotiation of Keys (KINK)' to Proposed Standard (fwd)



On Wed, Nov 30, 2005 at 12:24:13PM -0500, Sam Hartman wrote:
> >>>>> "KAMADA" == KAMADA Ken'ichi <kamada@xxxxxxxxxx> writes:
> 
> 
>     KAMADA> The KINK_ENCRYPT payload is tied with AP-REQ (or AP-REP)
>     KAMADA> with the Cksum field.  I thought it is enough to prevent
>     KAMADA> reflection.  Isn't it?
> 
> I believe so.

Yes, I had not noticed that all KINK messages have an AP-REQ, AP-REP or
KRB-ERROR.

Nico
--