Re: Length of pre-shared key

Dan Harkins <dharkins@tibernian.com> Mon, 25 February 2002 17:39 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g1PHda303755; Mon, 25 Feb 2002 09:39:36 -0800 (PST)
Received: by lists.tislabs.com (8.9.1/8.9.1) id LAA25514 Mon, 25 Feb 2002 11:56:57 -0500 (EST)
Message-Id: <200202251706.g1PH6Xr00398@fatty.lounge.org>
To: juha.ollila@nokia.com
Cc: ipsec@lists.tislabs.com
Subject: Re: Length of pre-shared key
In-Reply-To: Your message of "Mon, 25 Feb 2002 16:41:20 +0200." <B49318639A71D3418DC1005FD40B36100EB4B9@ouebe005.NOE.Nokia.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-ID: <395.1014656793.1@tibernian.com>
Date: Mon, 25 Feb 2002 09:06:33 -0800
From: Dan Harkins <dharkins@tibernian.com>
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

  IKE uses the pre-shared key as the key to an HMAC. RFC2104 specifies
that the key to an HMAC should not be less than the output of the under-
lying hash function. So if you're using HMAC-SHA that's 20 bytes.

  Dan.

On Mon, 25 Feb 2002 16:41:20 +0200 you wrote
> 	Hello!
> 
> Have IPsec and IKE specifications any requirements about the pre-shared keys?
> I didn't find the required length of pre-shared key.
> 
> Best Regards,
> Juha Ollila