IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: additional core draft nits in need of WG attention.



Bill Sommerfeld <sommerfeld%east.sun.com@localhost> writes:

> [wg chair hat on]
> 
> I see a kernel of consensus building for:
>  - leave recommended limit at 128 bits
>  - explicitly grandfather 3DES

Exactly what does "grandfather" mean here? Change 3DES from REQUIRED
to RECOMMENDED? Or OPTIONAL? Or DEPRECATED? To me, it makes sense to
keep it as RECOMMENDED.

> [now that I re-read this section of transport-17, we have an editing
> glitch]:
> 
>    The "diffie-hellman-group1-sha1" method specifies Diffie-Hellman key
>    exchange with SHA-1 as HASH, and Oakley group 14 [RFC3526]
>    (2048-bit MODP Group).  It is included below in hexadecimal and decimal.
> 
> And it then specifies the group 1 modulus..

I guess the name for dh with Oakley group 14 would be
"diffie-hellman-group14-sha1". Or should we go for
"diffie-hellman-group14-sha256" while we're at it? Unfortunately,
there's more than one reasonable choice here.

Regards,
/Niels



Home | Main Index | Thread Index | Old Index