Re: 112 bit 3DES

Sandy Harris <sandy.harris@sympatico.ca> Wed, 28 April 1999 22:42 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by mail.proper.com (8.8.8/8.8.5) with ESMTP id PAA29940; Wed, 28 Apr 1999 15:42:41 -0700 (PDT)
Received: by lists.tislabs.com (8.9.1/8.9.1) id NAA04820 Wed, 28 Apr 1999 13:54:59 -0400 (EDT)
Message-ID: <37274D62.793FBB79@sympatico.ca>
Date: Wed, 28 Apr 1999 14:03:14 -0400
From: Sandy Harris <sandy.harris@sympatico.ca>
X-Mailer: Mozilla 4.5 [en]C-SYMPA (Win95; U)
X-Accept-Language: en,fr-CA
MIME-Version: 1.0
To: ipsec@lists.tislabs.com
Subject: Re: 112 bit 3DES
References: <A0550295565ED211A13B00A0C9A7918906A3CA@mail.altiga.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

"Volpe, Victor" wrote:
 
> According to the 3DES draft "draft-ietf-ipsec-ciph-des3-00.txt", 112 bit
> 3DES must not be negotiated via IKE and is therefore a non-compliant key
> length for 3DES.  Did I read this correctly?  What is the status of the
> draft?

RFC 2409, page 38:

    The key for 3DES-CBC is the first twenty-four (24) bytes of a key
    derived in the aforementioned pseudo-random function feedback method.