[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Another pothole in ISAKMP/Oakley



Another pothole of note in ISAKMP is Diffie-Hellman
small-subgroup confinement.

Although ISAKMP refers to X9.42, which I believe will
have a description of how to avoid the problem, it
should also probably be mentioned in some IETF document
relevant to DH in ISAKMP.  There are just too many published
descriptions of DH that fail to mention the problem, so that
there's a good chance of trapping an unwary implementor.

-- David



Follow-Ups: References: