[TLS] Issue 49: Finished.verify length
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[TLS] Issue 49: Finished.verify length
Pasi asks:
Currently Finished.verify_data is always 12 octets. With newer PRFs
and hashes, more might be useful. Should this depend on the PRF?
My take on this is that the 12-octet length is mostly independent
of the PRF. After all, it's already been truncated from either
MD5 or SHA-1. Is there a good security reason to change this?
-Ekr
_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.