[openssl.org #3260] Several issues with hash algorithm selection in cipher suites

2014-09-04 Thread Rich Salz via RT
We are implementing that the IETF RFC's specify. Closing ticket. -- Rich Salz, OpenSSL dev team; rs...@openssl.org __ OpenSSL Project http://www.openssl.org Development Mailing List

Re: [openssl.org #3260] Several issues with hash algorithm selection in cipher suites

2014-02-09 Thread Aaron Jones
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 09/02/14 10:09, Peter Backes via RT wrote: > SHA512 is not offered at all To the best of my knowlege, there is no ciphersuite that uses SHA-512, either in OpenSSL, or in the RFCs. OpenSSL cannot implement a ciphersuite until identifiers for it h

[openssl.org #3260] Several issues with hash algorithm selection in cipher suites

2014-02-09 Thread Peter Backes via RT
This is a copy from https://bugzilla.redhat.com/show_bug.cgi?id=1062924 According to "Recommendation for Key Management," NIST Special Publication 800-57 Part 1 Rev. 3, 07/2012, one should use twice the number of bits of hash as the number of key bits in block cipher. For example, use a SHA256