[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Issue 66: HMAC-256 based ciphersuites



One more argument for adding those ciphersuites, is that they allow increasing the security level of a connection to more than 128 bits. Now the weakest link in a TLS session seems to be the HMAC, if all the other parameters are negotiated using a 256 bit equivalent security.

Although 256-bit security level might seem too much, I'd note that we already have AES-256.

On Jan 1, 2008 12:49 AM, Eric Rescorla < ekr@xxxxxxxxxxxxxxxxxxxx> wrote:
Someone, I can't remember who, suggested that we add
HMAC-SHA256-based ciphersuites (i.e., ones that use it as a message
MAC) directly in TLS 1.2. I'm waffling as to whether it's a good
idea.

Arguments for:

- We made it the default for the PRF.
- It's weird to to to all this trouble and not define them.


Arguments against:
- There's nothing known wrong with HMAC-SHA1
- This revision is about flexibility, not actually adding new
 digests.

Comments?

-Ekr


_______________________________________________
TLS mailing list
TLS@xxxxxxxxxxxxxx
https://www1.ietf.org/mailman/listinfo/tls

_______________________________________________
TLS mailing list
TLS@xxxxxxxxxxxxxx
https://www1.ietf.org/mailman/listinfo/tls