GSSAPI FIPS compliant AES encryption

Griff James 1 Reputation point
2022-12-14T10:23:44.677+00:00

Are there any plans in the pipeline to update MSFT's GSSAPI implementation to add support for AES-256 encryption?

I know that no RFC currently exists for this, the strongest session key supported by the RFCs is 3DES which is deprecated.

On a related note the NTLMv2, SMB and NETLOGON protocols are also lagging behind with only AES-128 being supported. Any plans to update these as well?

thx

Windows Open Specifications
Windows Open Specifications
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.Open Specifications: Technical documents for protocols, computer languages, standards support, and data portability. The goal with Open Specifications is to help developers open new opportunities to interoperate with Windows, SQL, Office, and SharePoint.
42 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,834 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.