Issue 8647 - support of weak ciphers according to rfc4513
Summary: support of weak ciphers according to rfc4513
Status: VERIFIED FIXED
Alias: None
Product: OpenLDAP
Classification: Unclassified
Component: slapd (show other issues)
Version: unspecified
Hardware: All All
: --- normal
Target Milestone: ---
Assignee: OpenLDAP project
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-04-27 14:18 UTC by sharathyadav123@gmail.com
Modified: 2017-04-27 16:01 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this issue.
Description sharathyadav123@gmail.com 2017-04-27 14:18:55 UTC
Full_Name: Sharath Yadav C
Version: 
OS: 
URL: ftp://ftp.openldap.org/incoming/
Submission from: (NULL) (125.17.165.38)


According to RFC4513

B.2.10.  Section 10 ("TLS Ciphersuites")

   - TLS ciphersuite recommendations are no longer included in this
     specification.  Implementations must now support the
     TLS_RSA_WITH_3DES_EDE_CBC_SHA ciphersuite and should continue to
     support the TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA ciphersuite.

   - Clarified that anonymous authentication involves a name value of
     zero length and a password value of zero length.  The
     unauthenticated authentication mechanism was added to handle simple
     Bind requests involving a name value with a non-zero length and a
     password value of zero length.


But actually 3DES is a weak cipher and it should not be used for any version,
but still rfc recommends to use the same which may cause security issues.
Comment 1 Howard Chu 2017-04-27 15:23:27 UTC
published 8647
marked public
Comment 2 Quanah Gibson-Mount 2017-04-27 16:00:40 UTC
Hello,

Thanks for your report.  The IETF is the correct organization to report RFC 
issues to, rather than the OpenLDAP Foundation.  I would suggest you 
redirect this to them.  This ITS will be closed.

Regards,
Quanah

--

Quanah Gibson-Mount
Product Architect
Symas Corporation
Packaged, certified, and supported LDAP solutions powered by OpenLDAP:
<http://www.symas.com>


Comment 3 OpenLDAP project 2017-04-27 16:01:47 UTC
IETF issue, not OpenLDAP
Comment 4 Quanah Gibson-Mount 2017-04-27 16:01:47 UTC
changed notes
changed state Open to Closed