Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: linux-ipsec: parity

From: Henry Spencer <henry%spenford(at)zoo.toronto.edu>
Date: Sat Mar 21 1998 - 00:50:11 EST


>What should happen when an IKE daemon (say, Pluto) discovers a weak key?

Sayeth ciph-cbc-02:

   Weak key checks SHOULD be performed. If such a key is found, the    key SHOULD be rejected and a new SA requested.

Similar words are found in des-expiv-01. This would seem to indicate that failure and renegotiation is intended here.

Interestingly enough, isakmp-oakley-07 (appendix B) says:

   The key for DES-CBC is derived from the first eight (8) non-weak and    non-semi-weak (see Appendix A) bytes of SKEYID_e.

which would seem to indicate that when setting up the misleadingly-named ISAKMP SA, one should fall back to later bits in some ill-defined manner (advance one byte? advance eight bytes?). The situation is likely to be so rare that we may never know if we interoperate on this...

Henry Received on Sat Mar 21 01:38:45 1998

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:28 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library