Re: deprecate tripleDES?

Michael Ströder <[email protected]> Sat, 24 Jan 2015 10:03:09 +0100
Newsgroups gmane.ietf.smime
Message-ID <[email protected]>
Paul Hoffman wrote:
> On Jan 3, 2015, at 4:32 AM, Michael Ströder <[email protected]> wrote:
>> Isn't it the time to deprecate using tripleDES and add a stronger SHOULD for
>> using stronger symmetric ciphers?
> 
> Why? I have not seen any attacks on TripleDES that make it insecure.
> 
>> The text from https://tools.ietf.org/html/rfc5751#section-2.7.1.2 is pretty
>> blurry:
>>
>>   [..] If the sending agent
>>   chooses not to use AES-128 in this step, it SHOULD use tripleDES.
> 
> If there are two or more ways to interpret that sentence, we can clarify
> it. I don't see more than one, but maybe I'm missing something.

Lazy implementors can read this section like:
"It's fine to only implement tripleDES and not support anything else forever."

Ciao, Michael.

_______________________________________________
smime mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/smime
smime.p7s (application/pkcs7-signature, 4.2 KB) - not displayed