1 Feb 2006 13:29
review of draft-eastlake-sha2-01.txt
<john.loughney <at> nokia.com>
2006-02-01 12:29:22 GMT
2006-02-01 12:29:22 GMT
Brian filed a discuss on this - I agree with it: >Discuss: >11. Security Considerations > > This document is intended to provide convenient open source access by > the Internet community to the United States of America Federal > Information Processing Standard Secure Hash Algorithms (SHAs) [FIPS > 180-2] and HMACs based thereon. > >"open source access"? RFCs don't carry an open source license. >I believe this should just read "open access". I note that the Abstract says: Abstract The United States of America has adopted a suite of secure hash algorithms (SHAs), including four beyond SHA-1, as part of a Federal Information Processing Standard (FIPS), specifically SHA-224 [RFC 3874], SHA-256, SHA-384, and SHA-512. The purpose of this document is to make open source code performing these hash functions conveniently available to the Internet community. .... I think this should be updated accordingly as well. John
I iterated with a couple of the authors (Wes & Ethan). None of us
really understands how we skipped 3 of the PILC RFCs. (This is
particularly embarrassing for me.) But, Ethan is going to write some
stuff for these RFCs and will look over the tweaks you suggested, too, I
am sure.
Some day this "simple" non-engineering document may be done ...
Thanks a bunch for the review.
allman
RSS Feed