IETF-SSH archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: additional core draft nits in need of WG attention.
Bill Sommerfeld <sommerfeld%east.sun.com@localhost> writes:
> [wg chair hat on]
>
> I see a kernel of consensus building for:
> - leave recommended limit at 128 bits
> - explicitly grandfather 3DES
Exactly what does "grandfather" mean here? Change 3DES from REQUIRED
to RECOMMENDED? Or OPTIONAL? Or DEPRECATED? To me, it makes sense to
keep it as RECOMMENDED.
> [now that I re-read this section of transport-17, we have an editing
> glitch]:
>
> The "diffie-hellman-group1-sha1" method specifies Diffie-Hellman key
> exchange with SHA-1 as HASH, and Oakley group 14 [RFC3526]
> (2048-bit MODP Group). It is included below in hexadecimal and decimal.
>
> And it then specifies the group 1 modulus..
I guess the name for dh with Oakley group 14 would be
"diffie-hellman-group14-sha1". Or should we go for
"diffie-hellman-group14-sha256" while we're at it? Unfortunately,
there's more than one reasonable choice here.
Regards,
/Niels
Home |
Main Index |
Thread Index |
Old Index