[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Crypto agility in SCRAM + draft-josefsson-password-auth?
Simon Josefsson wrote:
> There is some progress on HMAC attacks [1].
> Are there any comments on the quality of that paper?
Put them in a draft, please, when you find them.
> SHA-1 is not covered by the SHA-2 patent as far as
> I have understood.
The patent is not the issue, the certification is.
Please correct me if I got this wrong, but I think
the plan is to find a new "good" hash until 2012,
and to phase out SHA-1 until 2010. For some value
of "good" not yet published in an Internet draft.
Frank