[saag] Re: [Ext] Re: draft-paulwh-crypto-components-02
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Christian Huitema <[email protected]> wrote: > I think the mention of NIST here is a bit of distraction, focusing on > administrative issues instead of technology. Over time, I have seen a > different concern, based on the life time of algorithm. At some unpredictable > time in the future, any algorithm may become broken by some innovative > attack. If all implementations implemented only that algorithm, all > implementations will become vulnerable until they get updated and start > supporting a different algorithm. But if implementations supported two > different algorithms, they can instead immediately switch to the non-broken > algorithm. And, the mechanisms to choose (and configure) the algorithms can get ossified if not excercized. I really like what IPsec(ME) has done with SHOULD+/MUST-, etc, and I rather wish this could become IETF-wide practice. -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE----- iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmez9Q0WHG1jcitpZXRm QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZXHeB/0bde1N5YFEeY9/OY+eATfuSxeK IYFAWOXTYgrqOO69np9ZhwyJX+vxPXmNUPKnej4/0v2zvVUVU3P1mpEgIiaRsQlj I2zdJjCW7ts6ZDTcYzQtci+YwNPmMumDNYBNJyID0QAqCjCSt/hAuoX+jK+/51YF JJsMi0XgLT9TzGEKIVoLCiKV/eyBVaqGmZqOM6v2POR9sEUwtOd5+S6yX0Cj5rxN BMvlms1BvTFr2kyIOIX8MymwvtnXXRsJIejMzkL2qRG1DPzs9f+UFlztGvctdnc0 Uoss9qlCQjurOzfI4PgdEPLcn3ocJGYiQTdB0qGE1MkHvAQ+Qq4k8rdhmZJB =H1BD -----END PGP SIGNATURE-----