2 Apr 2007 09:15
draft-ietf-krb-wg-pkinit-alg-agility-02 review
Shawn M Emery <Shawn.Emery <at> Sun.COM>
2007-04-02 07:15:50 GMT
2007-04-02 07:15:50 GMT
Here is my review of draft-ietf-krb-wg-pkinit-alg-agility-02: Overall: This is improved from the previous revision that I read. Thanks. Abstract: Replace SHA with SHA-1 Introduction: Add RFC reference to "... 3.2.3 of [RFC4556] ..." Are there any length limits for the Introductions? Don't nonces in the protocol negate the affect of potential collisions? 6. KDF agility New update drafts have to be created as new KDFs become available? nit: "cryptographic bindings" should be "cryptographic binding" nit: "thus addresses" should be "thus addressing" Why are the "...," strings defined? What if the id request is disjoint from the supported list by the server? Why is pkinit-kdf-ah-sha256 the limiting algorithm? 7. Security Considerations(Continue reading)
RSS Feed