Return-Path: <era@x500.eu>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 1BD6E3A090D
 for <spasm@ietfa.amsl.com>; Thu, 30 Apr 2020 07:39:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.696
X-Spam-Level: 
X-Spam-Status: No, score=-1.696 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1,
 HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001,
 URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=neutral
 reason="invalid (public key: not available)" header.d=x500.eu
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id cIefRAqLXbdz for <spasm@ietfa.amsl.com>;
 Thu, 30 Apr 2020 07:39:52 -0700 (PDT)
Received: from outscan1.mf.dandomain.dk (outscan1.mf.dandomain.dk
 [212.237.249.58])
 (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 7240E3A0908
 for <spasm@ietf.org>; Thu, 30 Apr 2020 07:39:51 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1])
 by outscan1.mf.dandomain.dk (Postfix) with ESMTP id 3E2FA4069186
 for <spasm@ietf.org>; Thu, 30 Apr 2020 16:39:50 +0200 (CEST)
Received: from outscan1.mf.dandomain.dk ([127.0.0.1])
 by localhost (outscan1.mf.dandomain.dk [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id Z1JGk9fXA14G for <spasm@ietf.org>;
 Thu, 30 Apr 2020 16:39:49 +0200 (CEST)
Received: from mail-proxy.dandomain.dk (dilvs03.dandomain.net [194.150.112.64])
 by outscan1.mf.dandomain.dk (Postfix) with ESMTPA id 3A9CD406917C
 for <spasm@ietf.org>; Thu, 30 Apr 2020 16:39:49 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=x500.eu;
 s=dandomain; t=1588257589;
 bh=VDW8f0iWI30lzan/rJRteTfCqAMcjG3P5s01qAUdnec=;
 h=From:To:References:In-Reply-To:Subject:Date:From;
 b=p9c5VMESLuOLXL6WqclcWU2z59VkphjE7l2NBve5PwaTEAcBZE/6friJFDePQ4ZM1
 rwBp0j77FO420zaJxnQhbu9Ae79rdkVSKnmt5hhjmYDw1XFkJIyTH9/1aA0jVT7I3f
 /7kL1GSoaHfRPvlrd5SBQXfdm7jo3MaM6BEpJtkw8U9PEL5kpqgvg/8Nv7M85JMUjp
 jCnOn06AuFw+SGlibhcGRdSJTtk7JAZNJgvy5WcDoG0moZ/LR9AhHTxTsCqDgS4swe
 9y8EjDLPuvHyqZ5wUkPBLjpumS/oZxx3Exx8bf20HXooLeyW+VvUD2ND8o0rYmDlxt
 9ih7jy4QcbHKw==
From: "Erik Andersen" <era@x500.eu>
To: "LAMPS" <spasm@ietf.org>
References: <001301d61ebe$ba9b2e80$2fd18b80$@x500.eu>
 <5CB31AAA-B35E-4F28-B0B0-FE0EEFC6EBFE@vigilsec.com>
In-Reply-To: <5CB31AAA-B35E-4F28-B0B0-FE0EEFC6EBFE@vigilsec.com>
Date: Thu, 30 Apr 2020 16:39:49 +0200
Message-ID: <002301d61efd$339f5ed0$9ade1c70$@x500.eu>
MIME-Version: 1.0
Content-Type: multipart/alternative;
 boundary="----=_NextPart_000_0024_01D61F0D.F7282ED0"
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQIeXTH8vmX/yjfa7b81JlFsI9TmBQIuclCip+/Ag4A=
Content-Language: en-gb
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/7nY2f2NeRTSyH9T0zf2Ea4yd1U0>
Subject: Re: [lamps] MAC (or ICV) generation
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime
 \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>,
 <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>,
 <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Apr 2020 14:39:55 -0000

This is a multipart message in MIME format.

------=_NextPart_000_0024_01D61F0D.F7282ED0
Content-Type: text/plain;
	charset="US-ASCII"
Content-Transfer-Encoding: 7bit

Hi Russ,

 

Thanks for the information. However, that was not my question.

 

Erik 

 

From: Russ Housley <housley@vigilsec.com> 
Sent: 30 April 2020 15:23
To: Erik Andersen <era@x500.eu>
Cc: LAMPS <spasm@ietf.org>
Subject: Re: [lamps] MAC (or ICV) generation

 

If you use an AEAD, the encryption and integrity check are one operations,
but the authentication tag (a.k.a. ICV) needs to have a place to be carried
in the PDU.

 

If you are using separate encryption and integrity algorithms, you will find
HMAC, CMAC, KMAC, and GMAC in use in different contexts.  There are probably
more.

 

Russ

 

 

On Apr 30, 2020, at 3:12 AM, Erik Andersen <era@x500.eu <mailto:era@x500.eu>
> wrote:

 

What is best when generating a MAC (also called Integrity Check Value or
ICV) over an PDU to be encrypted: Generating the ICV over the clear text or
over the encrypted text?

 

Best regards,

 

Erik

 


------=_NextPart_000_0024_01D61F0D.F7282ED0
Content-Type: text/html;
	charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii"><meta name=3DGenerator content=3D"Microsoft Word 15 =
(filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DDA link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span =
style=3D'mso-fareast-language:EN-US'>Hi Russ,<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'mso-fareast-language:EN-US'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span lang=3DEN-GB =
style=3D'mso-fareast-language:EN-US'>Thanks for the information. =
However, that was not my question.<o:p></o:p></span></p><p =
class=3DMsoNormal><span lang=3DEN-GB =
style=3D'mso-fareast-language:EN-US'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span lang=3DEN-GB =
style=3D'mso-fareast-language:EN-US'>Erik <o:p></o:p></span></p><p =
class=3DMsoNormal><span lang=3DEN-GB =
style=3D'mso-fareast-language:EN-US'><o:p>&nbsp;</o:p></span></p><div><di=
v style=3D'border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm =
0cm 0cm'><p class=3DMsoNormal><b><span =
lang=3DEN-US>From:</span></b><span lang=3DEN-US> Russ Housley =
&lt;housley@vigilsec.com&gt; <br><b>Sent:</b> 30 April 2020 =
15:23<br><b>To:</b> Erik Andersen &lt;era@x500.eu&gt;<br><b>Cc:</b> =
LAMPS &lt;spasm@ietf.org&gt;<br><b>Subject:</b> Re: [lamps] MAC (or ICV) =
generation<o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal>If you use =
an AEAD, the encryption and integrity check are one operations, but the =
authentication tag (a.k.a. ICV) needs to have a place to be carried in =
the PDU.<o:p></o:p></p><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>If you are using separate encryption and integrity =
algorithms, you will find HMAC, CMAC, KMAC, and GMAC in use in different =
contexts. &nbsp;There are probably more.<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>Russ<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p class=3DMsoNormal =
style=3D'margin-bottom:12.0pt'><o:p>&nbsp;</o:p></p><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal>On Apr 30, 2020, at 3:12 AM, Erik Andersen &lt;<a =
href=3D"mailto:era@x500.eu">era@x500.eu</a>&gt; =
wrote:<o:p></o:p></p></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><div><p =
class=3DMsoNormal><span lang=3DEN-GB>What is best when generating a MAC =
(also called Integrity Check Value or ICV) over an PDU to be encrypted: =
Generating the ICV over the clear text or over the encrypted =
text?</span><o:p></o:p></p></div><div><p class=3DMsoNormal><span =
lang=3DEN-GB>&nbsp;</span><o:p></o:p></p></div><div><p =
class=3DMsoNormal><span lang=3DEN-GB>Best =
regards,</span><o:p></o:p></p></div><div><p class=3DMsoNormal><span =
lang=3DEN-GB>&nbsp;</span><o:p></o:p></p></div><div><p =
class=3DMsoNormal><span =
lang=3DEN-GB>Erik</span><o:p></o:p></p></div></div></blockquote></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div></div></body></html>
------=_NextPart_000_0024_01D61F0D.F7282ED0--

