[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Re: SIV as WG item?




On Jan 14, 2008, at 11:42 AM, Simon Josefsson wrote:

<Pasi.Eronen@xxxxxxxxx> writes:

Simon Josefsson wrote:

Generally speaking, I believe the crypto community will produce
several AEAD cipher modes with rather different properties (speed,
IV-use, provable security, patent status, and so on).

Having all those ciphers defined for TLS is an advantage, to allow
interoperable testing.  What is less clear at this point is which of
the alternatives to prefer.

Many of the arguments made in the recent discussion about IDEA
(e.g., more code means more complexity and less security in
practise, especially if some of that code is rarely used and thus
largely untested; and having too many "vanity" options just causes
problems) would suggest that having *all* those ciphers defined in
TLS would not be a such good idea.

I think there is a significant difference between the IDEA situation and the AEAD situation: the IDEA ciphersuites are mentioned in the core TLS
specification.  We should (rightly) be more conservative about any
complexity complications in the core document.

As far as I have understood, no single AEAD ciphersuite will be
recommended or specified in the TLS 1.2 specification.

If so, having multiple informational documents on different AEAD
ciphersuites leads to simpler real-world-like comparisons between them.
When we have had some time to evaluate these, and have let the crypto
community scrutinize the various different AEAD modes for some time, we
can chose a small set of them (possibly a single one) to promote to
standards track status.

However, I don't feel strongly about this, and this is just my gut
reaction on how I would prefer to do it.  There may be some compelling
arguments for doing it in some other way that I haven't considered.


That gives the writers of OpenSSL/GnuTLS/Windows CAPI no guidance. I think if we do that, the result would be not what the cyrpto community scrutinizes, but what Microsoft did and OpenSSL copied.



_______________________________________________
TLS mailing list
TLS@xxxxxxxxxxxxxx
https://www1.ietf.org/mailman/listinfo/tls