Comments on the current AES draft

Wes Hardaker <[email protected]> Tue, 07 Oct 2003 15:34:37 -0700
Newsgroups gmane.ietf.snmpv3
Organization Sparta
Message-ID <[email protected]>
I had a few comments on the current aes-usm draft.  I noticed it has
gone through 2 revisions since last call, and I just noticed it is in
IESG review but here they are anyway.  First off, the draft is much
better worded and clearer than the last time I read it, so thanks to
the authors for doing a nice job.

- I find the discussion in section 1.2 and 1.3 a bit confusing because
  it doesn't paint a clear picture of how passwords get converted into
  master keys (Ku) and then converted into localized keys (Kul).  I
  understand it as is but only because I adequately understand the
  semantics with how the USM keying mechanisms work.  It would be
  better, IMHO, if you tie the wording together with RFC3414 a bit
  better.

- 1.3: "Implementation SHOULD support the use of randomly generated
  passwords as a stronger form of security".  I think you mean
  "randomly generated keys" (Ku) instead here.

- Section 3.1.2.1 4th paragraph: The problem is much more prevalent
  when considering a large number of agents sending INFORMs to a
  manager, which is a much more likely case for a IV collision than a
  few managers to a large number of agents.  The odds are still remote
  for "todays technology" but a few decades (2ish, maybe less) out it
  might be more of a problem.

- Section 4: Security Considerations.  The first paragraph basically
  says that all the SHOULDs in section 1.3 MUST be implemented.  This
  certainly MUST/SHOULD be corrected before publication as an RFC.

-- 
Wes Hardaker
Sparta