[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Derived versus Explicit IV



>  4) A change to explicit IV would "obsolete" thousands of fielded units,
>     and create a user support nightmare.

Yes.

The draft ESP spec, combined with the ciph-des-derived spec, is compatible
with the 32-bit-IV option in RFC 1827+1829, which in turn is the most
commonly implemented transform. The ciph-des-expiv is *not* compatible with
old implementations, due to the addition of the mandatory sequence number
field in the ESP header.

If the new ESP plus new mandatory to implement transforms are *not*
backwards compatible *ON THE WIRE*, then a new IP protocol value for ESP
will be required.

-- 
Harald Koch <chk@utcc.utoronto.ca>


Follow-Ups: References: