Re: Subsession keys (Re: KINK issue list)
Michael Thomas <[email protected]> Mon, 31 Jan 2005 16:43:29 -0800
| Newsgroups | gmane.ietf.kink |
|---|---|
| Organization | Cisco Systems |
| Message-ID | <[email protected]> |
On Thu, 2005-01-27 at 00:17, KAMADA Ken'ichi wrote: > At Thu, 20 Jan 2005 11:04:48 +0900, > "KAMADA Ken'ichi" <[email protected]> wrote: > > > > [*] Subsession keys (section 5 and 8) > > > > Are subsession keys ignored? (Ken Raeburn) > > I think they should not be ignored. I'm hopelessly behind here, but I don't think I saw a response to this... why should they be taken into account? We're already mixing in entropy from the kdc and the ipsec peers. What is more entropy in the form of subsession keys buying us? Or am I missing the point? Mike
signature.asc
(application/pgp-signature, 307 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iQCVAwUAQf7QsbMsDAj/Eq++AQJiJgP/RraKTMoSpaBaFr3CwUyGLXGhlQ7557nM 8diU3kAJ79hty3NlH9Xab/u/icCir/yy5PtsI1vmfgpuTyjohnNDbgdmOecqGEQS wkx6LJ3a2wCD7FnxyPWXAoK/RfZiNea5BGbi83bX4BufLEBpoausdWH2nvXvPmgk HBzm53JoAc8= =8SGE -----END PGP SIGNATURE-----