RE: [Ipsec] CMAC Documents

Pasi.Eronen@nokia.com Thu, 09 June 2005 14:01 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1DgNbB-0006QA-Sn; Thu, 09 Jun 2005 10:01:33 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1DgNb9-0006Q5-FZ for ipsec@megatron.ietf.org; Thu, 09 Jun 2005 10:01:31 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA02504 for <ipsec@ietf.org>; Thu, 9 Jun 2005 10:01:29 -0400 (EDT)
From: Pasi.Eronen@nokia.com
Received: from mgw-ext03.nokia.com ([131.228.20.95]) by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1DgNwb-0004cf-K3 for ipsec@ietf.org; Thu, 09 Jun 2005 10:23:43 -0400
Received: from esebh107.NOE.Nokia.com (esebh107.ntc.nokia.com [172.21.143.143]) by mgw-ext03.nokia.com (Switch-3.1.7/Switch-3.1.7) with ESMTP id j59Dx1ow025030; Thu, 9 Jun 2005 16:59:01 +0300
Received: from esebh103.NOE.Nokia.com ([172.21.143.33]) by esebh107.NOE.Nokia.com with Microsoft SMTPSVC(6.0.3790.1830); Thu, 9 Jun 2005 17:01:05 +0300
Received: from esebe105.NOE.Nokia.com ([172.21.143.53]) by esebh103.NOE.Nokia.com with Microsoft SMTPSVC(6.0.3790.1830); Thu, 9 Jun 2005 17:01:05 +0300
X-MimeOLE: Produced By Microsoft Exchange V6.5.7226.0
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Subject: RE: [Ipsec] CMAC Documents
Date: Thu, 09 Jun 2005 17:01:04 +0300
Message-ID: <B356D8F434D20B40A8CEDAEC305A1F24CD2ECE@esebe105.NOE.Nokia.com>
Thread-Topic: [Ipsec] CMAC Documents
Thread-Index: AcVsRQGhqfMrSzSVQEGpB9senNl67gAtmPag
To: housley@vigilsec.com, ipsec@ietf.org
X-OriginalArrivalTime: 09 Jun 2005 14:01:05.0547 (UTC) FILETIME=[ADA01DB0:01C56CFB]
X-Spam-Score: 0.3 (/)
X-Scan-Signature: 0ddefe323dd869ab027dbfff7eff0465
Content-Transfer-Encoding: quoted-printable
Cc:
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: IP Security <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
Sender: ipsec-bounces@ietf.org
Errors-To: ipsec-bounces@ietf.org

A comment about draft-songlee-aes-cmac-prf-128-00: 

Some features of IKEv2 work, well, poorly with PRFs that
require a fixed size key (see draft-eronen-ipsec-ikev2-
clarifications-03, Sections 2.8, 2.9, and 3.5 for details).
Currently we have only one such PRF (AES-XCBC-PRF-128), but 
there's work ongoing (draft-hoffman-rfc3664bis-02) to remove 
the fixed key size restriction from XCBC-MAC (by specifying 
how to get a 128-bit key from a shorter or longer key).

I think it would be useful to include such processing in
CMAC-PRF as well (so from IKEv2 point of view, it would accept
a key of arbitrary length).

Best regards,
Pasi

(BTW, the draft also needs an IANA considerations section.)

> -----Original Message-----
> From: Russ Housley
> Sent: Wednesday, June 08, 2005 6:55 PM
> To: ipsec@ietf.org
> Subject: [Ipsec] CMAC Documents
> 
> Dear IPsec Mail List:
> 
> I am going to shepherd these documents.  As a first step, I 
> would appreciate your review and comment.
> 
> Thanks,
>   Russ
> 
> 
>
> Hi Russ Housley,
> 
> We have I-Ds which are AES-CMAC usage on IPsec, but it has no
> workgroup since IPsec workgroup completed last April.
>
> Can you possibly shepherd it for standard track publication?
>
> http://www.ietf.org/internet-drafts/draft-songlee-aes-cmac-96-02.txt 
> http://www.ietf.org/internet-drafts/draft-songlee-aes-cmac-prf-128-00.txt 
> 
> Thanks,
> Jun Hyuk Song 

_______________________________________________
Ipsec mailing list
Ipsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec