RE: FW: DISCUSS: draft-ietf-ipcdn-bpiplus-mib-14
Russ Housley <[email protected]>
| Newsgroups | gmane.ietf.ipcdn |
|---|---|
| Message-ID | <[email protected]> |
Jean-Francois: > > I seriously doubt that t3DES128EdeMode is useful in this > > context. ECB had > ^^^ >you mean EDE here > > some properties that are probably bad in this environment. > >Okay, we can remove it, no pb. Okay. >Just fyi, 3DES EDE was also proposed because it is already used in the >BPI+ spec for the traffic encryption key (TEK). See page 21 of BPI+ at >http://www.cablemodem.com/downloads/specs/BPI+_I11-040407.pdf : >"The traffic encryption key (TEK) in the Key Reply is triple DES >(encrypt-decrypt-encrypt or EDE mode) encrypted, using a two-key, triple >DES key encryption key (KEK) derived from the Authorization Key." This is still a poor choice. See RFC 3217 and RFC 3394 for better solutions. Russ