Re: [lamps] MAC (or ICV) generation
Erik Andersen <era@x500.eu> Thu, 30 April 2020 14:39 UTC
Return-Path: <era@x500.eu>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1BD6E3A090D for <spasm@ietfa.amsl.com>; Thu, 30 Apr 2020 07:39:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.696
X-Spam-Level:
X-Spam-Status: No, score=-1.696 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=neutral reason="invalid (public key: not available)" header.d=x500.eu
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cIefRAqLXbdz for <spasm@ietfa.amsl.com>; Thu, 30 Apr 2020 07:39:52 -0700 (PDT)
Received: from outscan1.mf.dandomain.dk (outscan1.mf.dandomain.dk [212.237.249.58]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7240E3A0908 for <spasm@ietf.org>; Thu, 30 Apr 2020 07:39:51 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by outscan1.mf.dandomain.dk (Postfix) with ESMTP id 3E2FA4069186 for <spasm@ietf.org>; Thu, 30 Apr 2020 16:39:50 +0200 (CEST)
Received: from outscan1.mf.dandomain.dk ([127.0.0.1]) by localhost (outscan1.mf.dandomain.dk [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z1JGk9fXA14G for <spasm@ietf.org>; Thu, 30 Apr 2020 16:39:49 +0200 (CEST)
Received: from mail-proxy.dandomain.dk (dilvs03.dandomain.net [194.150.112.64]) by outscan1.mf.dandomain.dk (Postfix) with ESMTPA id 3A9CD406917C for <spasm@ietf.org>; Thu, 30 Apr 2020 16:39:49 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=x500.eu; s=dandomain; t=1588257589; bh=VDW8f0iWI30lzan/rJRteTfCqAMcjG3P5s01qAUdnec=; h=From:To:References:In-Reply-To:Subject:Date:From; b=p9c5VMESLuOLXL6WqclcWU2z59VkphjE7l2NBve5PwaTEAcBZE/6friJFDePQ4ZM1 rwBp0j77FO420zaJxnQhbu9Ae79rdkVSKnmt5hhjmYDw1XFkJIyTH9/1aA0jVT7I3f /7kL1GSoaHfRPvlrd5SBQXfdm7jo3MaM6BEpJtkw8U9PEL5kpqgvg/8Nv7M85JMUjp jCnOn06AuFw+SGlibhcGRdSJTtk7JAZNJgvy5WcDoG0moZ/LR9AhHTxTsCqDgS4swe 9y8EjDLPuvHyqZ5wUkPBLjpumS/oZxx3Exx8bf20HXooLeyW+VvUD2ND8o0rYmDlxt 9ih7jy4QcbHKw==
From: Erik Andersen <era@x500.eu>
To: LAMPS <spasm@ietf.org>
References: <001301d61ebe$ba9b2e80$2fd18b80$@x500.eu> <5CB31AAA-B35E-4F28-B0B0-FE0EEFC6EBFE@vigilsec.com>
In-Reply-To: <5CB31AAA-B35E-4F28-B0B0-FE0EEFC6EBFE@vigilsec.com>
Date: Thu, 30 Apr 2020 16:39:49 +0200
Message-ID: <002301d61efd$339f5ed0$9ade1c70$@x500.eu>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_0024_01D61F0D.F7282ED0"
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQIeXTH8vmX/yjfa7b81JlFsI9TmBQIuclCip+/Ag4A=
Content-Language: en-gb
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/7nY2f2NeRTSyH9T0zf2Ea4yd1U0>
Subject: Re: [lamps] MAC (or ICV) generation
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Apr 2020 14:39:55 -0000
Hi Russ, Thanks for the information. However, that was not my question. Erik From: Russ Housley <housley@vigilsec.com> Sent: 30 April 2020 15:23 To: Erik Andersen <era@x500.eu> Cc: LAMPS <spasm@ietf.org> Subject: Re: [lamps] MAC (or ICV) generation If you use an AEAD, the encryption and integrity check are one operations, but the authentication tag (a.k.a. ICV) needs to have a place to be carried in the PDU. If you are using separate encryption and integrity algorithms, you will find HMAC, CMAC, KMAC, and GMAC in use in different contexts. There are probably more. Russ On Apr 30, 2020, at 3:12 AM, Erik Andersen <era@x500.eu <mailto:era@x500.eu> > wrote: What is best when generating a MAC (also called Integrity Check Value or ICV) over an PDU to be encrypted: Generating the ICV over the clear text or over the encrypted text? Best regards, Erik
- [lamps] MAC (or ICV) generation Erik Andersen
- Re: [lamps] MAC (or ICV) generation Russ Housley
- Re: [lamps] MAC (or ICV) generation Erik Andersen
- Re: [lamps] MAC (or ICV) generation Salz, Rich
- Re: [lamps] MAC (or ICV) generation Erik Andersen