1996-03-28 - Re: HP & Export of DCE

From: David Weisman <weisman@osf.org>
UTC Datetime: 1996-03-28 03:49:17 UTC
Raw Date: Thu, 28 Mar 1996 11:49:17 +0800

From: David Weisman <weisman@osf.org>
Date: Thu, 28 Mar 1996 11:49:17 +0800
Subject: Re: HP & Export of DCE
On Wed Mar 27, 1996, Perry E. Metzger wrote:

    Adam Shostack writes:

    > | Adam Shostack writes:
    > | > Well, if Leahy passes, DCE is exportable.

DCE is exported today, although without the ability to encrypt application
traffic.  Authentication and message integrity are in the export version.

    They are attacks against Diffie-Hellman. I don't know if DCE uses D-H
    in a similar manner. The main problem was too small a (fixed) modulus.
DCE RPC uses Kerberos V5 to establish DES session keys.