Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: linux-ipsec: problems, part 3

From: Angelos D. Keromytis <angelos(at)dsl.cis.upenn.edu>
Date: Thu Mar 05 1998 - 14:27:41 EST


-----BEGIN PGP SIGNED MESSAGE----- To: Richard Guy Briggs <rgb@conscoop.flora.org> Subject: Re: linux-ipsec: problems, part 3 Cc: henry@zoo.utoronto.ca, linux-ipsec@clinet.fi Date: 03/05/98, 14:27:40

In message <199803051839.NAA22967@conscoop.flora.org>, Richard Guy Briggs write s:
>Which command is this 'feature' used in?

Any command that takes a key, I believe.

>It looks as though the whole key is used for generating the 3 des keys,
>the iv (for constant IV), the HMAC key and ipad and rpad which I assume
>are initiator and responder related, all hashed.

Oh. That. So there's probably a very ugly s&d mechanism in there, which needs to be completely removed.

>This is (admittedly) new territory. This code looks quite deliberate
>so I assume it is either done on purpose or borrowed. It is quite
>different from the OpenBSD code and the description in rfc2104.

Yes. That code is ancient.

  • -Angelos

-----BEGIN PGP SIGNATURE-----

Version: 2.6.3i
Charset: noconv
Comment: Processed by Mailcrypt 3.4, an Emacs/PGP interface
Do you need help?X

iQCVAwUBNP78rL0pBjh2h1kFAQEm8AQAkeC+gn+wkRanG5oJhlaDGrbDmcBeh8pQ wcD8Xg5t2KG2O/jtOeTqxyy1lO3ETz+Rzd36m7OsxgpckvCEPG3Tx96rid0NalEh 0LNNhuVWGyTbrRp+RKQUQWyZI1yj7mrhVvxTDJDakI8e1d2v7RBale17UONEPCZp mAJoulYp9fo=
=IV53
-----END PGP SIGNATURE----- Received on Thu Mar 5 14:42:14 1998

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:28 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library