[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Cfrg] Re: Changing the key deriveration



Ted,

I'll try to wrap up the discussion and move on a summary that we can 
agree on, in a separate mail.

David

On Feb 24, 2004, at 11:50 AM, Theodore Ts'o wrote:

> On Fri, Feb 20, 2004 at 06:09:58PM -0800, Paul Hoffman / VPNC wrote:
>> At 9:57 PM +0200 2/17/04, Hugo Krawczyk wrote:
>>> Anyway, replacing SK_ai and SK_ar in the above text (as well as in 
>>> 2.15,
>>> first paragraph) with SK_d does resolve the problem of using two
>>> algorithms (prf and integrity) with the same key, and it is much 
>>> better
>>> than what is done now.
>>
>> There have been no more comments on this, and the ADs are still
>> waiting for a final draft of this document so they can move all three
>> IKEv2 documents to IETF last call.
>
> David and Ran --- is the CFRG currently working on some kind of
> official statement that represents the consensus of the group, or
> should we use the comments made by CFRG members in our deliberations?
> If the former, could you give us a timeline when the official comments
> from the CFRG can be expected?  If the latter, please accept the
> thanks of the IPSEC working group to those members who took the time
> to evaluate Hugo's proposal.
>
> 						- Ted
>
> _______________________________________________
> Cfrg mailing list
> Cfrg@ietf.org
> https://www1.ietf.org/mailman/listinfo/cfrg
>