IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: SHA-2 based HMAC algorithm...



"Mark D. Baushke" <mdb%juniper.net@localhost> writes:

>For what it is worth, if we are going to give a few mor options, addressing
>some of the other issues raised by NIST SP 800-131 might be wise.
>
>[...]

Hmm, are you sure you want to try and get all that in an RFC?  The amount of
bikeshedding this'll entail will be monumental, while just defining a few new
strings for SHA-256 to complement the existing SHA-1 ones should be fairly
quick.  I guess it depends on what the urgency is, the SHA-1 -> SHA-256 quick
fix could be done as a fast-path RFC and then the bikeshedding-magnet change-
other-bits-of-the-crypto could be done as a longer-term one.

Peter.



Home | Main Index | Thread Index | Old Index