[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ike and elliptic curves



>There has been concern on this mailing list in the past that the
>groups might be too small.

the groups are not necessarily too small, but of questionable security (they
were excluded by ansi and the national institute of standards and technology)
and don't align with the fips curves as well. we've actually submitted a draft:

draft-ietf-ipsec-ike-ecc-groups-00.txt

to address this. cheers - john

---------------------- Forwarded by John Harleman/Certicom on 10.11.1999 20:06
---------------------------


Niels Provos <provos@citi.umich.edu> on 10.11.1999 18:14:29

To:   jerome@psti.com
cc:   ipsec@lists.tislabs.com (bcc: John Harleman/Certicom)
Subject:  Re: ike and elliptic curves




In message <19991110151358.A6224@jerome.psti.com>, jerome@psti.com writes:
>i would like to know which vendors implements the elliptics curves
>group of ike.
The free isakmpd implementation that is part of OpenBSD supports the
two specified elliptic curve groups.  You can find the sources at

  http://www.openbsd.org/cgi-bin/cvsweb/src/sbin/isakmp/

There has been concern on this mailing list in the past that the
groups might be too small.  The two mails that I cound find in my
archive refering to that are:

     <E0z6zWL-0006Yo-00@wserver.physnet.uni-hamburg.de>
     <35D380DF.1F7B4A62@Certicom.com>

Greetings,
 Niels.