[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: New 12288 and 16384 bit groups



trevp@trevp.net (Trevor Perrin) writes:
> Out of curiosity, are the primes currently in 
> draft-ietf-ipsec-ike-modp-groups-05 proven to be safe primes (of the form 
> N=2q+1, where q is prime), or just proven to be prime?

All the groups in the draft-ietf-ipsec-ike-modp-groups-05 are proven
to be safe primes (i.e both the p and the (p - 1) / 2 are proven to be
prime). The ECPP/primo certificates can be found at
http://ftp.ssh.com/pub/ietf/ecpp-certificates/ (that url used to be in
the draft, but was removed because url's are not stable enough to be
used as references (that url is going to be stable :-)). 
-- 
kivinen@ssh.fi
SSH Communications Security                  http://www.ssh.fi/
SSH IPSEC Toolkit                            http://www.ssh.fi/ipsec/