Re: Subsession keys (Re: KINK issue list)

Michael Thomas <[email protected]> Mon, 31 Jan 2005 16:43:29 -0800
Newsgroups gmane.ietf.kink
Organization Cisco Systems
Message-ID <[email protected]>
On Thu, 2005-01-27 at 00:17, KAMADA Ken'ichi wrote:
> At Thu, 20 Jan 2005 11:04:48 +0900,
> "KAMADA Ken'ichi" <[email protected]> wrote:
> > 
> > [*] Subsession keys (section 5 and 8)
> > 
> > 	Are subsession keys ignored?  (Ken Raeburn)
> 
> I think they should not be ignored.

I'm hopelessly behind here, but I don't think I saw
a response to this... why should they be taken into
account? We're already mixing in entropy from the kdc
and the ipsec peers. What is more entropy in the form
of subsession keys buying us? Or am I missing the point?

		Mike
signature.asc (application/pgp-signature, 307 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iQCVAwUAQf7QsbMsDAj/Eq++AQJiJgP/RraKTMoSpaBaFr3CwUyGLXGhlQ7557nM
8diU3kAJ79hty3NlH9Xab/u/icCir/yy5PtsI1vmfgpuTyjohnNDbgdmOecqGEQS
wkx6LJ3a2wCD7FnxyPWXAoK/RfZiNea5BGbi83bX4BufLEBpoausdWH2nvXvPmgk
HBzm53JoAc8=
=8SGE
-----END PGP SIGNATURE-----