Paul,good points, I'm convinced that it would be better to dump AES-192 from the spec.
David On May 8, 2006, at 9:12 AM, Paul Hoffman wrote:
At 12:15 PM -0700 5/4/06, David McGrew wrote:The main motivation for AES-192 and AES-256 is to provide alternative ciphers to AES-128 that can be adopted in event that unforeseen advances in cryptanalysis significantly erode the security level ofAES-128.The downside of proposing multiple alternative ciphers, as compared to just one, is that it is likely that implementers will not do interop testing on all of them. It is much better to propose just one fall-back cipher. This is particularly true for AES, as we have discovered in the VPNC test lab.For IETF standards where AES-128 is a MUST-level requirement, there should be just one fall-back, AES-256, with wording like the "SHOULD +" definitions in RFC 4307.--Paul Hoffman, Director --VPN Consortium
Note Well: Messages sent to this mailing list are the opinions of the senders and do not imply endorsement by the IETF.