3DES-CBC-MAC

Ben Rogers <ben@Ascend.COM> Tue, 16 September 1997 11:17 UTC

Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id HAA03754 for ipsec-outgoing; Tue, 16 Sep 1997 07:17:56 -0400 (EDT)
Date: Tue, 16 Sep 1997 01:58:01 -0400
Message-Id: <199709160558.BAA00898@carp.morningstar.com>
From: Ben Rogers <ben@Ascend.COM>
To: ipsec@tis.com, isakmp-oakley@cisco.com
Subject: 3DES-CBC-MAC
Reply-To: ben@Ascend.COM
Sender: owner-ipsec@ex.tis.com
Precedence: bulk

IO-RES seems to assume we have a knowledge of 3DES-CBC-MAC, but doesn't
provide a reference for the used implementation.  Some of the other
drafts reference Schneier (IMO an unacceptable reference for an internet
draft) for DES-CBC-MAC.  However, we don't really have a well defined
method to create padding bits if the last block does not end on an 8
byte boundary.

Am I missing some reference in the docs?

Otherwise can someone please explain to the list what is typically done
here, and append that to the IO-RES draft?


ben