[Ipsec] Comments about draft-solinas-ui-suites-00

<Pasi.Eronen@nokia.com> Mon, 11 December 2006 08:59 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1Gth0S-0004GC-O9; Mon, 11 Dec 2006 03:59:28 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1Gth0Q-0004Fu-2m for Ipsec@ietf.org; Mon, 11 Dec 2006 03:59:26 -0500
Received: from smtp.nokia.com ([131.228.20.172] helo=mgw-ext13.nokia.com) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1Gth0O-00013U-L0 for Ipsec@ietf.org; Mon, 11 Dec 2006 03:59:26 -0500
Received: from esebh108.NOE.Nokia.com (esebh108.ntc.nokia.com [172.21.143.145]) by mgw-ext13.nokia.com (Switch-3.2.5/Switch-3.2.5) with ESMTP id kBB8wmIw009483; Mon, 11 Dec 2006 10:59:00 +0200
Received: from esebh103.NOE.Nokia.com ([172.21.143.33]) by esebh108.NOE.Nokia.com with Microsoft SMTPSVC(6.0.3790.1830); Mon, 11 Dec 2006 10:59:16 +0200
Received: from esebe105.NOE.Nokia.com ([172.21.143.53]) by esebh103.NOE.Nokia.com with Microsoft SMTPSVC(6.0.3790.1830); Mon, 11 Dec 2006 10:59:15 +0200
X-MimeOLE: Produced By Microsoft Exchange V6.5
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Date: Mon, 11 Dec 2006 10:59:16 +0200
Message-ID: <B356D8F434D20B40A8CEDAEC305A1F240381F7F3@esebe105.NOE.Nokia.com>
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: Comments about draft-solinas-ui-suites-00
Thread-Index: AccdAqLrPmwwN76TT6uiS+D4SL0OUA==
From: Pasi.Eronen@nokia.com
To: Ipsec@ietf.org, lelaw@orion.ncsc.mil, jasolin@orion.ncsc.mil
X-OriginalArrivalTime: 11 Dec 2006 08:59:15.0785 (UTC) FILETIME=[A2903B90:01C71D02]
X-Nokia-AV: Clean
X-Spam-Score: 0.2 (/)
X-Scan-Signature: 856eb5f76e7a34990d1d457d8e8e5b7f
Cc:
Subject: [Ipsec] Comments about draft-solinas-ui-suites-00
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: IP Security <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
Errors-To: ipsec-bounces@ietf.org

A couple of minor comments about this draft:

1) The document needs a reference to draft-kelly-ipsec-ciph-sha2,
which specifies how to use SHA-256 with IPsec.

2) Currently draft-kelly-ipsec-ciph-sha2 specifies only SHA-256 
based integrity/PRF algorithms, but not SHA-384 or SHA-512, so 
"Suite-B-GCM-256" and "Suite-B-GMAC-256" are not actually
implementable using currently existing documents.

3) Given that SHA-384 is basically SHA-512 truncated to 384 bits 
(and with different IV), do we really need e.g. a SHA-384 based 
PRF for IKEv2? Wouldn't it be simpler just to use SHA-512?
(There are applications where using SHA-384 may make sense, but 
I'm not sure IKEv2 PRF is one of them...)

Best regards,
Pasi

_______________________________________________
Ipsec mailing list
Ipsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec