Re: [TLS] Last Call: draft-ietf-tls-rfc4346-bis (The Transport
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] Last Call: draft-ietf-tls-rfc4346-bis (The Transport
Eric Rescorla wrote:
>
> At Tue, 4 Mar 2008 09:58:29 -0800,
> Paul Hoffman wrote:
> >
> > At 6:19 AM -0500 3/4/08, Rob Dugal wrote:
> > >section 7.4.1.4.1
> > >
> > >Why is SHA-224 not supported as a HashAlgorithm? For completeness
> > >shouldn't TLS 1.2 support all the SHA-2 algorithms?
> >
> > Not everyone agrees with the utility of SHA-224, particularly in a
> > protocol where AES-128 is mandatory to implement.
>
> Indeed.
>
> If you want a MAC with effective algorithmic security the same as
> SHA-256 but shorter, that's what truncated MACs are for.
SHA-224 is effectively that:
SHA-224 is based on SHA-256, but it uses an different
initial value and the result is truncated to 224 bits.
-Martin
_______________________________________________
TLS mailing list
TLS at ietf.org
https://www.ietf.org/mailman/listinfo/tls
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.