[TLS] Issue 49: Finished.verify length
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[TLS] Issue 49: Finished.verify length



Pasi asks:

  Currently Finished.verify_data is always 12 octets. With newer PRFs
  and hashes, more might be useful. Should this depend on the PRF?
  
My take on this is that the 12-octet length is mostly independent
of the PRF. After all, it's already been truncated from either 
MD5 or SHA-1. Is there a good security reason to change this?

-Ekr

_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.