Thread (6 messages) 6 messages, 3 authors, 2008-12-29

Re: [PATCH] [IPSEC]: Change the ICV length of sha256 to 128 bits

From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2008-12-29 20:48:01

On Mon, Dec 29, 2008 at 02:05:19PM +0100, Martin Willi wrote:
In PF_KEY, SADB_X_AALG_SHA2_256HMAC (5) was defined in
draft-ietf-ipsec-ciph-sha-256-00 to 96 bit truncation (what is currently
implemented). draft-ietf-ipsec-ciph-sha-256-01 defined it to 128 bit
truncation (what is now RFC 4868).
Those numbers starting from 12 are IKEv2 algorithm identifiers and are
never passed to the kernel.
What are you talking about? Neither of those two drafts talks
about the ID used between the KM and the kernel.  So the PF_KEY
ID is simply irrelevant.

What is important though is what's deployed in the field with
respect to IKE.  All the BSDs support 96-bit truncation so we
should continue to do that as well.

Cheers,
-- 
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} [off-list ref]
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help