Return-path: <ipsec-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
 by megatron.ietf.org with esmtp (Exim 4.43)
 id 1Ix1SC-000176-Ro; Tue, 27 Nov 2007 09:30:24 -0500
Received: from ipsec by megatron.ietf.org with local (Exim 4.43)
 id 1Ix1SB-00011i-Ts
 for ipsec-confirm+ok@megatron.ietf.org; Tue, 27 Nov 2007 09:30:23 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
 by megatron.ietf.org with esmtp (Exim 4.43) id 1Ix1SB-00011Z-KH
 for ipsec@lists.ietf.org; Tue, 27 Nov 2007 09:30:23 -0500
Received: from [2001:1bc8:100d::2] (helo=mail.kivinen.iki.fi)
 by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1Ix1SB-0003cj-5K
 for ipsec@lists.ietf.org; Tue, 27 Nov 2007 09:30:23 -0500
Received: from fireball.kivinen.iki.fi (localhost [127.0.0.1])
 by mail.kivinen.iki.fi (8.13.8/8.12.10) with ESMTP id lAREULX0023386
 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
 Tue, 27 Nov 2007 16:30:21 +0200 (EET)
Received: (from kivinen@localhost)
 by fireball.kivinen.iki.fi (8.13.8/8.12.11) id lAREUJ3A002809;
 Tue, 27 Nov 2007 16:30:19 +0200 (EET)
X-Authentication-Warning: fireball.kivinen.iki.fi: kivinen set sender to
 kivinen@iki.fi using -f
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <18252.10747.455107.780676@fireball.kivinen.iki.fi>
Date: Tue, 27 Nov 2007 16:30:19 +0200
From: Tero Kivinen <kivinen@iki.fi>
To: Michael Richardson <mcr@sandelman.ca>
Subject: [IPsec] Re: test vectors for IKEv2 SKEYSEED derivation
In-Reply-To: <fig8ap$do5$1@ger.gmane.org>
References: <fhe1bp$7h0$1@ger.gmane.org> <fia7cq$t93$1@ger.gmane.org>
 <18250.58764.542898.587852@fireball.kivinen.iki.fi>
 <fig8ap$do5$1@ger.gmane.org>
X-Mailer: VM 7.19 under Emacs 21.4.1
X-Edit-Time: 9 min
X-Total-Time: 9 min
X-Spam-Score: -1.4 (-)
X-Scan-Signature: 9182cfff02fae4f1b6e9349e01d62f32
Cc: ipsec@lists.ietf.org
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>,
 <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>,
 <mailto:ipsec-request@ietf.org?subject=subscribe>
Errors-To: ipsec-bounces@ietf.org

Michael Richardson writes:
> Well, the statement does apply to encryption algorithms (it says say that),
> but here, I understand you..

Oh, sorry, I didn't check the where you cut & pasted that text, I
assumed it was from 2.14 i.e. about SKEYSEED generation, but that was
from 2.13 i.e. from generating key material. So that text applies to
all of the things generated out from the SKEYSEED, i.e SK_d, SK_ai,
SK_ar, SK_ei, SK_er, SK_pi, and SK_pr.

> if we negotiated PRF_AES128_XCBC, then are you 
> saying that there would have had to be an attribute of "keysize=128" 
> included?  It seems that "128" is included in the name of the PRF?

No, we do not need keysize (and cannot have it) in that case, as the
PRF_AES128_XCBC is fixed key length algorith, that only accepts keys
of length of 128 bits, as defined in the section 4.1 of the RFC 3566
referenced from the section 2 of the RFC 3664 referenced from section
3.3.2 transform type 2 table of the RFC 4306.

Note, that it is not whether the underlaying algorithm can accept
variable length keys, it is whether the algorithm used in the IKE can
be used with variable lenght keys. 
-- 
kivinen@safenet-inc.com


_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec


