[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: DES-CBC "interface" shim



Bill,

A couple of comments on your DES-CBC "shim" document (which we're calling
"algorithm" documents in the AH and ESP I-Ds):

	- I'd suggest rewording the IV section to make it clear that the
IVs used here are not carried explicitly in the ESP packet, but are
constructed from values elsewhere in the ESP packet format, what the ESP
I-D refers to as an "implicit" IV.   Also, I hope your insistance on always
including the sequence number field, wasting 4 bytes in the IPv4 context if
anti-replay was not enabled, was not motivated by your desire to use it for
IV computation here.

	-I don't see a need to include section 7, on the authentication
data field.

Steve




References: