RE: FW: DISCUSS: draft-ietf-ipcdn-bpiplus-mib-14

Russ Housley <[email protected]>
Newsgroups gmane.ietf.ipcdn
Message-ID <[email protected]>
Jean-Francois:

> > I seriously doubt that t3DES128EdeMode is useful in this
> > context.  ECB had
>             ^^^
>you mean EDE here
> > some properties that are probably bad in this environment.
>
>Okay, we can remove it, no pb.

Okay.

>Just fyi, 3DES EDE was also proposed because it is already used in the
>BPI+ spec for the traffic encryption key (TEK). See page 21 of BPI+ at
>http://www.cablemodem.com/downloads/specs/BPI+_I11-040407.pdf :
>"The traffic encryption key (TEK) in the Key Reply is triple DES
>(encrypt-decrypt-encrypt or EDE mode) encrypted, using a two-key, triple
>DES key encryption key (KEK) derived from the Authorization Key."

This is still a poor choice.  See RFC 3217 and RFC 3394 for better solutions.

Russ
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.