[IPsec] Re: Fwd: I-D Action:draft-hoffman-ikev2bis-02.txt

Michael Richardson <mcr@sandelman.ca> Sat, 24 November 2007 22:55 UTC

Return-path: <ipsec-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1Iw3tv-0000MT-Je; Sat, 24 Nov 2007 17:55:03 -0500
Received: from ipsec by megatron.ietf.org with local (Exim 4.43) id 1Iw3tu-0000ML-Fq for ipsec-confirm+ok@megatron.ietf.org; Sat, 24 Nov 2007 17:55:02 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1Iw3tu-0000MD-3r for ipsec@lists.ietf.org; Sat, 24 Nov 2007 17:55:02 -0500
Received: from main.gmane.org ([80.91.229.2] helo=ciao.gmane.org) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1Iw3tr-0005Pg-Oc for ipsec@lists.ietf.org; Sat, 24 Nov 2007 17:55:02 -0500
Received: from list by ciao.gmane.org with local (Exim 4.43) id 1Iw3tm-0003Om-AY for ipsec@lists.ietf.org; Sat, 24 Nov 2007 22:54:54 +0000
Received: from wlan197.sandelman.ca ([209.87.252.197]) by main.gmane.org with esmtp (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for <ipsec@lists.ietf.org>; Sat, 24 Nov 2007 22:54:54 +0000
Received: from mcr by wlan197.sandelman.ca with local (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for <ipsec@lists.ietf.org>; Sat, 24 Nov 2007 22:54:54 +0000
X-Injected-Via-Gmane: http://gmane.org/
To: ipsec@lists.ietf.org
From: Michael Richardson <mcr@sandelman.ca>
Date: Sat, 24 Nov 2007 17:54:39 -0500
Lines: 36
Message-ID: <4748ABAF.7020500@sandelman.ca>
References: <p0624080cc364f8d726b4@[165.227.249.203]>
Mime-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Complaints-To: usenet@ger.gmane.org
X-Gmane-NNTP-Posting-Host: wlan197.sandelman.ca
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.0.12) Gecko/20070510 Iceape/1.0.9 (Debian-1.0.9-0etch1)
In-Reply-To: <p0624080cc364f8d726b4@[165.227.249.203]>
X-Spam-Score: -0.0 (/)
X-Scan-Signature: 39bd8f8cbb76cae18b7e23f7cf6b2b9f
Cc:
Subject: [IPsec] Re: Fwd: I-D Action:draft-hoffman-ikev2bis-02.txt
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
Errors-To: ipsec-bounces@ietf.org

Paul Hoffman wrote:
>    In Section 2.13, replaced text about variable length keys with
>    clearer explanation and requirement on non-HMAC PRFs.  Also added
>    "preferred" to Section 2.14 for the key length, and removed redundant
>    text.
> 
>    In Section 2.14, removed the "half and half" description and replaced
>    it with exceptions for RFC4434 and RFC4615.
> 
>    Removed the now-redundant "All PRFs used with IKEv2 MUST take
>    variable-sized keys" from Section 2.15.

okay, these clarifications helped me just now, and answer the questions for 
the email that I posted ten minutes ago.

Tero, based upon this, is your SKEYSEED input you sent me correct?

SshIkev2Crypto/ikev2-crypto.c:328/test_ikev2_skeyseed_agree: Key for PRF (Ni 
| Nr)
00000000: b5ce 8419 095c 6e2b 6b62 d305 5305 b3c4  .....\n+kb..S...
00000010: 47e9 f925 8ca2 3858 f675 b166 b02c c292  G..%..8X.u.f.,..

My inputs were:

unsigned char tc2_ni[] = {
  0xb5, 0xce, 0x84, 0x19,  0x09, 0x5c, 0x6e, 0x2b,
  0x6b, 0x62, 0xd3, 0x05,  0x53, 0x05, 0xb3, 0xc4,
};
unsigned char tc2_nr[] = {
  0x47, 0xe9, 0xf9, 0x25,  0x8c, 0xa2, 0x38, 0x58,
  0xf6, 0x75, 0xb1, 0x66,  0xb0, 0x2c, 0xc2, 0x92,
};

and this was md5, so the key size is 16 bytes.
You have an input key size of 32 bytes.




_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec