[IPsec] [Technical Errata Reported] RFC7634 (5441)

2018-07-27 Thread Tero Kivinen
RFC Errata System writes: > The following errata report has been submitted for RFC7634, > "ChaCha20, Poly1305, and Their Use in the Internet Key Exchange Protocol > (IKE) and IPsec". > > -- > You may review the report below and at: > http://www.rfc-editor.org/e

Re: [IPsec] [Technical Errata Reported] RFC7634 (5441)

2018-07-27 Thread Valery Smyslov
Hi, while this clarification wouldn't hurt if it were present in the RFC 7634, I think that generally speaking it is redundant. RFC 7634 doesn't exist in vacuum, it is expected that its readers are familiar with RFC 7296, which has a clear rule that algorithms with fixed key size MUST NOT include

Re: [IPsec] [Technical Errata Reported] RFC7634 (5441)

2018-07-27 Thread Benjamin Kaduk
On Thu, Jul 26, 2018 at 10:06:30PM +0300, Yoav Nir wrote: > This errata proposes to add the following sentence to section 4 of RFC 7634 > : > > As with other transforms that use a fixed-length key, the Key Length > attribute MUST NOT be specified. >

Re: [IPsec] [Technical Errata Reported] RFC7634 (5441)

2018-07-27 Thread Tobias Brunner
Hi Paul, > Some note would be good because apparently strongswan insists of the > KEY_LENGTH attribute they shouldn’t be there? Yes, we did that incorrectly before 5.6.3 [1]. Since then the key length attribute is omitted, but it's still possible to add a transform with it to a proposal by using

Re: [IPsec] [Technical Errata Reported] RFC7634 (5441)

2018-07-26 Thread Paul Wouters
Some note would be good because apparently strongswan insists of the KEY_LENGTH attribute they shouldn’t be there? Sent from my phone > On Jul 26, 2018, at 12:06, Yoav Nir wrote: > > This errata proposes to add the following sentence to section 4 of RFC 7634: > > As with other transforms that

Re: [IPsec] [Technical Errata Reported] RFC7634 (5441)

2018-07-26 Thread Yoav Nir
This errata proposes to add the following sentence to section 4 of RFC 7634 : As with other transforms that use a fixed-length key, the Key Length attribute MUST NOT be specified. This sentence is correct. If this came up as a suggestion during WG

[IPsec] [Technical Errata Reported] RFC7634 (5441)

2018-07-26 Thread RFC Errata System
The following errata report has been submitted for RFC7634, "ChaCha20, Poly1305, and Their Use in the Internet Key Exchange Protocol (IKE) and IPsec". -- You may review the report below and at: http://www.rfc-editor.org/errata/eid5441 -