> Another minor nit: you're referencing HMAC, > so you should add a reference to RFC 2104 > in which the HMAC construction is defined. No problem. I submitted a new version of the draft with references to RFC 2104 and RFC 4231: http://www.ietf.org/id/draft-dbider-sha2-mac-for-ssh-02.txt denis