|
|||||||||||
|
Re: linux-ipsec: broken for a few days...
From: <rob.glenn(at)nist.gov>
Date: Fri Aug 07 1998 - 08:11:43 EDT Come on folks, not yet another US government conspiracy theory in the making! Because of the controversy with AH, and the fact that ESP_NULL + <your favorite IPsec authentication algorithm> is, as far as we know at this time, equally as strong as AH with <same algorithm>, it was decided to make ESP_NULL a "mandatory to implement" algorithm (as specified in the DOI draft). I seriously doubt this will change. As far as implementing ESP_NULL, just make sure that it MUST be used WITH one of the specified authentication algorithms. Hell, don't even call it ESP_NULL, call it ESP_Authentication, if that will eleviate some of the fear and paranoia. As far as I know, NSA made no comments for or against and the US government only participated by letting me co-author a somewhat humorous draft with Steve Kent.
Rob G.
>Date: Fri, 7 Aug 1998 04:05:42 GMT
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:26 EDT |
||||||||||
|
|||||||||||