[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Cfrg] Re: Changing the key deriveration



On Fri, Feb 20, 2004 at 06:09:58PM -0800, Paul Hoffman / VPNC wrote:
> At 9:57 PM +0200 2/17/04, Hugo Krawczyk wrote:
> >Anyway, replacing SK_ai and SK_ar in the above text (as well as in 2.15,
> >first paragraph) with SK_d does resolve the problem of using two
> >algorithms (prf and integrity) with the same key, and it is much better
> >than what is done now.
> 
> There have been no more comments on this, and the ADs are still 
> waiting for a final draft of this document so they can move all three 
> IKEv2 documents to IETF last call.

David and Ran --- is the CFRG currently working on some kind of
official statement that represents the consensus of the group, or
should we use the comments made by CFRG members in our deliberations?
If the former, could you give us a timeline when the official comments
from the CFRG can be expected?  If the latter, please accept the
thanks of the IPSEC working group to those members who took the time
to evaluate Hugo's proposal.

						- Ted