Re: I-D Action:draft-ietf-krb-wg-pkinit-alg-agility-05.txt
Margaret Wasserman <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
Hi Kelley, On Feb 15, 2012, at 9:49 AM, Burgin, Kelley W. wrote: > Would you add id-pkinit-kdf-ah-sha384 to the list of new KDFs in section > 6? In Suite B, the 192-bit minimum level of security requires the use of > SHA-384 as its hash algorithm. Unless there is any objection from other members of the WG, I would be happy to add this. > I suggest using the text from 800-56A: > "reps = ceiling (keydatalen / hash length)" This would be clearer than what the document says now, and I will make this change. Just so you know, the way I received this document, it said: reps = keydatalen/hash length which was wrong. The current text reflects my attempt to fix that. I agree that your wording is a better way to say what I intended to say. > In step 4 of the KDF description, it's not clear that you truncate the > last block Hash_reps to get K bits. Suggest adding a sentence to this > effect when K/H is not and integer. I'll look at this. My guess is that most implementations will not actually truncate the last block, but that they will allocate a bigger buffer than they actually send, and just pass an appropriate length, so I'm trying to figure out a way to make this clear without attempting to mandate a particular way to implement it. Suggestions are welcome. I'll incorporate all of your other suggestions. Although mostly editorial, you caught a few things that will definitely improve the quality of the document. Thank you! Margaret _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg