RE: Comments on x942-05 draft

Russ Housley <housley@spyrus.com> Fri, 12 March 1999 10:37 UTC

Received: from mail.proper.com (mail.proper.com [206.86.127.224]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id FAA00089 for <smime-archive@odin.ietf.org>; Fri, 12 Mar 1999 05:37:31 -0500 (EST)
Received: (from majordomo@localhost) by mail.proper.com (8.8.8/8.8.5) id BAA08307 for ietf-smime-bks; Fri, 12 Mar 1999 01:20:42 -0800 (PST)
Received: from spyrus.com (mail.spyrus.com [207.212.34.30]) by mail.proper.com (8.8.8/8.8.5) with ESMTP id BAA08299 for <ietf-smime@imc.org>; Fri, 12 Mar 1999 01:20:38 -0800 (PST)
Received: from rhousley_laptop.spyrus.com (hil-qbu-ppu-vty45.as.wcom.net [209.154.55.45]) by spyrus.com (8.7.6/8.7.3/arc) with SMTP id BAA11224; Fri, 12 Mar 1999 01:26:01 -0800 (PST)
Message-Id: <4.1.19990311161546.00988e70@mail.spyrus.com>
Message-Id: <4.1.19990311161546.00988e70@mail.spyrus.com>
X-Sender: rhousley@mail.spyrus.com (Unverified)
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.1
Date: Thu, 11 Mar 1999 16:19:48 -0500
To: Burt Kaliski <burt@RSA.COM>
From: Russ Housley <housley@spyrus.com>
Subject: RE: Comments on x942-05 draft
Cc: ekr@rtfm.com, jlinn@securitydynamics.com, ietf-smime@imc.org
In-Reply-To: <7DE9F929113DD11181C900805F85C1AA6FDF94@geoduck.rsa.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Sender: owner-ietf-smime@imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Burt:

You are correct.  The corrent write-up does specify the content-encryption
algorithm OID.  I agree that we should replace the content-encryption
algorithm OID with the key-wrap algorithm OID.

Russ


At 01:07 PM 3/10/99 -0800, Burt Kaliski wrote:
>Dear Russ --
>
>Thanks for the CMS excerpt.
>
>My question is about the parameters to the X9.42 KDF, specifically the OID
>associated with the derived key. The field is defined as follows:
>
>	algorithm is the ASN.1 algorithm OID of the symmetric algorithm with
>which
>	     this KEK will be used. 
>
>I'm assuming that within CMS, the OID would be id-alg-CMS3DESwrap or
>id-alg-CMSRC2wrap.
>
>x942-05 is unclear about this, as "symmetric algorithm" might be interpreted
>as the OID for RC2 or triple-DES, not the key wrapping mechanism. I think
>it's better to identify the key wrapping mechanism, in case there's more
>than one with the same underlying symmetric algorithm. One risk, of course,
>is that the OID for the key wrapping mechansim might be too generic -- so
>there should be some way to include parameters (if any) to the key wrapping
>OID as input to the KDF.
>
>-- Burt
>
>
>> ----------
>> From: 	Russ Housley[SMTP:housley@spyrus.com]
>> Sent: 	Friday, March 05, 1999 10:05 AM
>> To: 	Burt Kaliski
>> Cc: 	Eric Rescorla; jlinn@securitydynamics.com
>> Subject: 	RE: Comments on x942-05 draft 
>> 
>> Burt:
>> 
>> Please take a look at CMS for this answer.  The AlgorithmIdentifier used
>> to
>> name Ephemeral-Static Diffie-Hellman has a parameter, and that parameter
>> specifies the key wrap algorithm.
>> 
>> Russ
>>