Re: [TLS] Issue 49: Finished.verify length
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Issue 49: Finished.verify length



At Fri, 14 Sep 2007 17:28:24 +0300,
<Pasi.Eronen at nokia.com> wrote:
> 
> Eric Rescorla wrote:
> 
> > I'm still trying to understand the rationale for why it makes sense
> > to have a verify_data != 12 bytes. Pasi, could you elaborate?
> 
> Again, I'm not suggesting changing it from 12 bytes; just allowing
> the agility to change it in the future without new TLS version.
> 
> One (somewhat hypothetical) use would be a cipher suite that tries 
> to have _everything_ at 256-bit security level (maybe for some 
> government approval reasons; not today, but maybe 5 years from now).
> 
> You might argue that this kind of security level isn't really
> needed, but then again, some people seem to be willing to go
> to great lengths to match these "security levels" (just think
> of SHA-224.. :-)

OK, I see where you're going with this, but I'm not sure it requires
us to do anything now. If we're confronted with such a cipher suite,
we can just have the document Update TLS 1.2, since it would only
be applicable to that new cipher suite. I don't think this needs
a version revision.

Unless you're proposing making this a variable length vector, whcih
seems like a bad idea, since it should be defined in the cipher
suite.
				   
-Ekr

_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.