Subject: Re: TCP-MD5
To: john heasley <heas@shrubbery.net>
From: Steven M. Bellovin <smb@research.att.com>
List: current-users
Date: 04/27/2004 20:50:59
In message <20040428000409.GK339@shrubbery.net>, john heasley writes:
>tcp(4):
>
> algorithm keylen (bits)
> tcp-md5 8 to 640 tcp: rfc2385
>
>Is that corrent, a minimum length of 8? Though silly, afaik all the
>router implementations i've touched have a minimum length of 1.
>
Actually see RFC 3562 for guidance. Also note that this is *bits* --
do the routers really permit a single-bit "key"? (I hesitate to use
the word "key" for something that short!)
--Steve Bellovin, http://www.research.att.com/~smb