[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[CAT HERDING] Key lengths for interoperability and security considerations



OK, so what needs to be done to come to closure on the key sizes. I think a
skeleton of The Right Thing looks something like this:

1. Normative language (MUST / SHOULD with lots of plusses and minuses and
   atsigns) describing the minimum and maximum lengths for keys. This covers
   the most important area of interoperability, and needs to be very clear
   about signing key lengths vs. verifying key lengths vs. generating key
   lengths.

2. An indication by those MUST / SHOULD statements pointing to the security
   considerations. This is the best we can do to guide people away from using
   one bit keys, and steer them in the direction of strong crypto.

3. Wording in the security considerations regarding the use of overshort or
   overlong keys.

Sean is preparing a summary of the existing discussion to address each point,
and we'll see where we're at.

Blake