IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: applying AES-GCM to secure shell: proposed "tweak"



--On Thursday, April 16, 2009 05:22:40 PM +0300 "Timo J. Rinne" <tri%ssh.com@localhost> wrote:

Additional option might be introducing a mac name (could actually be used
in ciphers and compressions too) that would be "fail-if-used". That would
be put to the tail if mac list if aead modes are used as possible
ciphers.  In case some other mac is selected with aead cipher, it's
simply dropped, if "fail-if-used" is selected with aead, it's dropped as
well.  In case "fail-if-used" mac gets selected with a traditional cipher
it will fail in some implementation dependant way.

That's an interesting approach.



Home | Main Index | Thread Index | Old Index