Re: [kitten] Fwd: New Version Notification for draft-kaduk-kitten-des-des-des-die-die-die-00.txt

Tom Yu <tlyu@mit.edu> Sun, 15 March 2015 21:45 UTC

Return-Path: <tlyu@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF8311A1B91 for <kitten@ietfa.amsl.com>; Sun, 15 Mar 2015 14:45:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hUg-6KK-evMo for <kitten@ietfa.amsl.com>; Sun, 15 Mar 2015 14:45:29 -0700 (PDT)
Received: from dmz-mailsec-scanner-2.mit.edu (dmz-mailsec-scanner-2.mit.edu [18.9.25.13]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2E6C91A1B8E for <kitten@ietf.org>; Sun, 15 Mar 2015 14:45:27 -0700 (PDT)
X-AuditID: 1209190d-f792d6d000001fc7-77-5505fd769b8f
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-2.mit.edu (Symantec Messaging Gateway) with SMTP id 30.A6.08135.67DF5055; Sun, 15 Mar 2015 17:45:26 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id t2FLjKAj018835; Sun, 15 Mar 2015 17:45:21 -0400
Received: from localhost (sarnath.mit.edu [18.18.1.190]) (authenticated bits=0) (User authenticated as tlyu@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t2FLjJ7u005581; Sun, 15 Mar 2015 17:45:20 -0400
From: Tom Yu <tlyu@mit.edu>
To: Benjamin Kaduk <kaduk@mit.edu>
References: <alpine.GSO.1.10.1503061501270.3953@multics.mit.edu>
Date: Sun, 15 Mar 2015 17:45:18 -0400
In-Reply-To: <alpine.GSO.1.10.1503061501270.3953@multics.mit.edu> (Benjamin Kaduk's message of "Fri, 6 Mar 2015 15:02:20 -0500")
Message-ID: <ldvk2yi0wb5.fsf@sarnath.mit.edu>
Lines: 9
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrMIsWRmVeSWpSXmKPExsUixCmqrFv2lzXU4NxxRYujm1exODB6LFny kymAMYrLJiU1J7MstUjfLoErY2HLfdaCG8wVi9Y1MDUw9jJ3MXJwSAiYSPQ/sO1i5AQyxSQu 3FvP1sXIxSEksJhJ4l5bFzuEs5FR4uX7m1DOG0aJSav3sYC0sAlISxy/vIsJxBYRUJJYfLaF DcRmFhCVOLfuCCuILSyQKXG56TWYLSTgIHFxay9YDYuAqsSyqcvB1nEKNDFKdH7oZQdJ8Aro SpzcP5kRxOYR4JDYe+cEK0RcUOLkzCcsEAu0JG78e8k0gVFgFpLULCSpBYxMqxhlU3KrdHMT M3OKU5N1i5MT8/JSi3SN9HIzS/RSU0o3MYLDT5J3B+O7g0qHGAU4GJV4eH+YsIYKsSaWFVfm HmKU5GBSEuX12QoU4kvKT6nMSCzOiC8qzUktPsQowcGsJMLL8g0ox5uSWFmVWpQPk5LmYFES 5930gy9ESCA9sSQ1OzW1ILUIJivDwaEkwVv9B6hRsCg1PbUiLTOnBCHNxMEJMpwHaHgtSA1v cUFibnFmOkT+FKMux50p/xcxCbHk5eelSonzJoEUCYAUZZTmwc2BpY1XjOJAbwnzXgWp4gGm HLhJr4CWMAEtqZ/OBLKkJBEhJdXAeN2nP/3Ob/VAlaV5e4Qzl8Zfv3fUbnXQa9fmB2yLhRVP y8jme773mbzn8DK5JLP761snXw+1MXzbLWH0+IDXK04e6asKhyc+TCr37jFnXTFBJ+9rZeq1 s7d4X3LtyFUT+3VDuXH2+/9J9rzsz7vztqkeflj6J+/VpoOufVadx/YF7Jl6Y5/XfiWW4oxE Qy3mouJEAKWT8gj2AgAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/z0YhKnmyRmimAhwrXBvefNRYvYc>
Cc: kitten@ietf.org
Subject: Re: [kitten] Fwd: New Version Notification for draft-kaduk-kitten-des-des-des-die-die-die-00.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 15 Mar 2015 21:45:31 -0000

Section 6.1: Several instances of des-cbc-sha1-kd should probably be
des3-cbc-sha1-kd.  On the other hand, RFC 3961 isn't consistent about
whether the algorithm name is des3-cbc-sha1-kd, des3-cbc-hmac-sha1-kd,
or des3-hmac-sha1-kd.

Also in Section 6.1: The single-DES enctype family doesn't use n-fold;
it uses a "fan-fold" that alternately reverses 56-bit chunks.  I think
the other observations in that section about the des3 string-to-key
algorithm are true.