Subject: Re: TCP-MD5
To: john heasley <heas@shrubbery.net>
From: Steven M. Bellovin <smb@research.att.com>
List: current-users
Date: 04/27/2004 20:50:59
In message <20040428000409.GK339@shrubbery.net>, john heasley writes:
>tcp(4):
>
>           algorithm       keylen (bits)
>           tcp-md5         8 to 640        tcp: rfc2385
>
>Is that corrent, a minimum length of 8?  Though silly, afaik all the
>router implementations i've touched have a minimum length of 1.
>
Actually see RFC 3562 for guidance.  Also note that this is *bits* -- 
do the routers really permit a single-bit "key"?  (I hesitate to use 
the word "key" for something that short!)

		--Steve Bellovin, http://www.research.att.com/~smb