Re: [Hipsec] [saag] NULL encryption mode in RFC 5202-bis

James Cloos <cloos@jhcloos.com> Tue, 08 July 2014 16:45 UTC

Return-Path: <cloos@jhcloos.com>
X-Original-To: hipsec@ietfa.amsl.com
Delivered-To: hipsec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EF5461B2BDB; Tue, 8 Jul 2014 09:45:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.652
X-Spam-Level:
X-Spam-Status: No, score=-2.652 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XERkGx-4_e_B; Tue, 8 Jul 2014 09:45:52 -0700 (PDT)
Received: from ore.jhcloos.com (ore.jhcloos.com [IPv6:2604:2880::b24d:a297]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 71A2A1B2BD9; Tue, 8 Jul 2014 09:45:52 -0700 (PDT)
Received: by ore.jhcloos.com (Postfix, from userid 10) id 4F8B21E4FB; Tue, 8 Jul 2014 16:45:50 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jhcloos.com; s=ore14; t=1404837950; bh=LyKNDrIC2MSZDnlTIUTVUl0gnsqu6lIGIsNx36ELOB4=; h=From:To:Cc:Subject:In-Reply-To:References:Date:From; b=hZal5QpXBJ2uz5mAd+tH4W6WPWCC4ClX8JvxgKJZwec0WVsbjZRvgW/OOQ2x3avmx MxDPtg0J8NrJ+8hziApcyYWI91ZqOFQmB+FCfQdrH62Zj/pzZF6cejfUvLcaPkfyMl lASD9nTRGhMsqXRv+MIGI0vPtkIQUi1tLLkwklfM=
Received: by carbon.jhcloos.org (Postfix, from userid 500) id 1AFA360022; Tue, 8 Jul 2014 16:37:29 +0000 (UTC)
From: James Cloos <cloos@jhcloos.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
In-Reply-To: <53BC0D30.2070507@cs.tcd.ie> (Stephen Farrell's message of "Tue, 08 Jul 2014 16:24:32 +0100")
References: <53BB798A.3080101@tomh.org> <m3lhs3dh5w.fsf@carbon.jhcloos.org> <53BC0D30.2070507@cs.tcd.ie>
User-Agent: Gnus/5.130012 (Ma Gnus v0.12) Emacs/24.4.50 (gnu/linux)
Face: iVBORw0KGgoAAAANSUhEUgAAABAAAAAQAgMAAABinRfyAAAACVBMVEX///8ZGXBQKKnCrDQ3 AAAAJElEQVQImWNgQAAXzwQg4SKASgAlXIEEiwsSIYBEcLaAtMEAADJnB+kKcKioAAAAAElFTkSu QmCC
Copyright: Copyright 2014 James Cloos
OpenPGP: 0x997A9F17ED7DAEA6; url=https://jhcloos.com/public_key/0x997A9F17ED7DAEA6.asc
OpenPGP-Fingerprint: E9E9 F828 61A4 6EA9 0F2B 63E7 997A 9F17 ED7D AEA6
Date: Tue, 08 Jul 2014 12:37:29 -0400
Message-ID: <m3fvibdcxi.fsf@carbon.jhcloos.org>
Lines: 18
MIME-Version: 1.0
Content-Type: text/plain
X-Hashcash: 1:30:140708:stephen.farrell@cs.tcd.ie::6rHADQ+2+3jnZE0d:00000000000000000000000000000000000ooP3q
X-Hashcash: 1:30:140708:tomh@tomh.org::VNj3cMxYoYrYEJUS:000COA7M
X-Hashcash: 1:30:140708:hipsec@ietf.org::2ftBm3dRcqFg2TKh:0oOyF7
X-Hashcash: 1:30:140708:saag@ietf.org::XWVrU0AADgxgZHQH:0009OEZW
Archived-At: http://mailarchive.ietf.org/arch/msg/hipsec/C4I1NgFPtxeDyWZrXgtSM0PfNKY
X-Mailman-Approved-At: Sun, 20 Jul 2014 05:30:24 -0700
Cc: hipsec@ietf.org, saag@ietf.org
Subject: Re: [Hipsec] [saag] NULL encryption mode in RFC 5202-bis
X-BeenThere: hipsec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the official IETF Mailing List for the HIP Working Group." <hipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/hipsec>, <mailto:hipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/hipsec/>
List-Post: <mailto:hipsec@ietf.org>
List-Help: <mailto:hipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hipsec>, <mailto:hipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Jul 2014 16:45:54 -0000

>>>>> "SF" == Stephen Farrell <stephen.farrell@cs.tcd.ie> writes:

SF> That'd be IPsec, not IP, I guess. How many people actually
SF> use IPsec that way?

I don't know.  AIUI, hams have been specified as a reason for NULL for
most ietf work product.

For this case, though, it seems Robert's suggestion of CMAC and GMAC may
be better long term.

Although there is stil the issue of compatibility with existing users,
if there are any.

-JimC
-- 
James Cloos <cloos@jhcloos.com>         OpenPGP: 0x997A9F17ED7DAEA6