Hi,

Am 22.03.2012 um 11:39 schrieb Henderson, Thomas R:

> This is the specific IESG comment:
> 
>   HIP defines the usage of RSA in signing and encrypting data.  Current
>   recommendations propose usage of, for example, RSA OAEP/PSS for these
>   operations in new protocols.  Changing the algorithms to more current
>   best practice should be considered.
> 
> RFC 4055 defines RSASSA-PSS and RSAES-OAEP keys.  Were these ever 
> discussed/considered as HIP key formats?
I cannot remember any discussion related to this. 

> This might be addressed by defining these as new algorithms in 5201-bis.
I agree. One could easily define a new suite. We could do that now or on 
demand. We need a new suite anyway to stay somewhat compatible with the 
existing HIP implementations.

Tobias


>  If someone with expertise on this topic could clarify what is needed to 
> address this comment, or could provide a pointer to how other IETF standards 
> have addressed this, I would appreciate it.  Otherwise, I will try to sketch 
> out a proposed solution.
> 



> - Tom
> _______________________________________________
> Hipsec mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/hipsec


-- 
Dr. Tobias Heer, Postdoctoral Researcher
Chair of Communication and Distributed Systems - comsys
RWTH Aachen University, Germany
tel: +49 241 80 207 76
web: http://www.comsys.rwth-aachen.de/team/tobias-heer/
blog: http://dtobi.wordpress.com/
card: http://card.ly/dtobi
pgp id: AEECA5BF 

_______________________________________________
Hipsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/hipsec

Reply via email to