String-to-Key Transformation
Kerberos 4 requires a transformation between the textual passwords that people remember and the 56-bit DES key that is actually used for encryption and decryption of the messages passed back and forth between client, KDC, and application server. This transformation is referred to as a string-to-key function, usually shortened to simply string2key . The transformation is very similar to the functions used to “encrypt” passwords in the standard Unix /etc/passwd file. It is a one-way hash function that, in the case of Kerberos 4, uses the principal’s password as input, and outputs a 56-bit hexadecimal DES key. Since the function is one way, it is mathematically very hard (read as impossible) to reverse the algorithm to deduce the password from the generated DES key. However, since this algorithm is public (and, indeed, must be widely known in order for different Kerberos implementations to interoperate), a brute-force or dictionary attack can be used to try passwords to find a matching DES key for a particular message.
The details of the string2key function are not particularly important to this discussion. If you’re interested in exactly how the transformation is performed, the string2key function is included in both the MIT and kth-krb Kerberos 4 distributions. In addition, kth-krb includes a kstring2key program that, given a password as input, outputs the hexadecimal DES key resulting from the string2key transformation.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access