[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: 40bit DES?



> > there seems to be 3 things needed for 'US exportable' IPsec:
> > 
> > A 40bit DES ESP algorithm
> > A 40bit DES for IKE
> > A 512 modulus for D-H
> > 
> > All three items handled by one draft might be called:
> 
> Only the first entry is required. You can leave the IKE encryption and D-H
> moduli (and RSA key strengths) at their normal, standard levels.
> 
> -- 
> Harald <chk@utcc.utoronto.ca>
> 

Very good point. Just to stress: the cryptographic strength of the 
algorithms in IKE has nothing to do with the strength of the data
encryption. It only determines the level of confidence in the 
authenticity and secrecy of the agreed key (however long or short it 
chooses to be). No reason to weaken that.

Ran



Follow-Ups: