IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: des-cbc cipher



Ran,

> Is this WG trying to make existing deployed SSHv2 implementations
> non-compliant with its current drafts ?

No.

To the best of my knowledge:

 1) before this discussion started, there was smooth working group
    consensus to avoid weak algorithms in the spec, single-DES included.

 2) i've seen zero interest in actually including des-cbc before this
    point was raised.

 3) The spec has never mentioned des-cbc.  This thread started when
    someone noticed that one implementation chose to use the (never
    officially allocated and thus out-of-spec) des-cbc algorithm name for
    single-DES.

We're behind schedule; building consensus to add des-cbc to the spec
(since I see substantial opposition) will make the documents even
later.

						- Bill



Home | Main Index | Thread Index | Old Index