Russ Allbery <[EMAIL PROTECTED]> writes:

> Keys based on user passwords should be fine.

However, I was just reminded that Kerberos password changes with Heimdal
similarly use OpenSSL to generate the session key, and therefore password
change sessions are subject to the same possible attack by brute-forcing
the random session key.

-- 
Russ Allbery ([EMAIL PROTECTED])               <http://www.eyrie.org/~eagle/>


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to