|
|||||||||||
|
Re: linux-ipsec: parity
From: Henry Spencer <henry%spenford(at)zoo.toronto.edu>
Date: Sat Mar 21 1998 - 00:50:11 EST
Sayeth ciph-cbc-02: Weak key checks SHOULD be performed. If such a key is found, the key SHOULD be rejected and a new SA requested. Similar words are found in des-expiv-01. This would seem to indicate that failure and renegotiation is intended here. Interestingly enough, isakmp-oakley-07 (appendix B) says: The key for DES-CBC is derived from the first eight (8) non-weak and non-semi-weak (see Appendix A) bytes of SKEYID_e. which would seem to indicate that when setting up the misleadingly-named ISAKMP SA, one should fall back to later bits in some ill-defined manner (advance one byte? advance eight bytes?). The situation is likely to be so rare that we may never know if we interoperate on this... Henry Received on Sat Mar 21 01:38:45 1998 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:28 EDT |
||||||||||
|
|||||||||||