[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Cfrg] Re: Changing the key deriveration



At 9:57 PM +0200 2/17/04, Hugo Krawczyk wrote:
>Anyway, replacing SK_ai and SK_ar in the above text (as well as in 2.15,
>first paragraph) with SK_d does resolve the problem of using two
>algorithms (prf and integrity) with the same key, and it is much better
>than what is done now.

There have been no more comments on this, and the ADs are still 
waiting for a final draft of this document so they can move all three 
IKEv2 documents to IETF last call.

Charlie: are you OK with this solution? If so, can you get the new 
draft out soon, such as when the Internet Drafts window opens?

--Paul Hoffman, Director
--VPN Consortium