Re: Public Review: NIST draft publication on extraction-then-expansion key derivation
Hugo Krawczyk <hugo <at> ee.technion.ac.il>
2010-11-01 16:07:56 GMT
Hi Tim,
I included the following point in comments I submitted to NIST, yet it may be worth repeating it here. SP 800-56C SEEMS to allow for the use of the technique standardized in RFC 5869. However, to arrive to that conclusion one has to carefully parse SP 800-56C as well as 800-108 and navigate the optional parts of these schemes. To avoid confusion and many questions in the future, I recommend that SP 800-56C (and preferably also the recent draft SP 800-135) EXPLICITLY mention the specific HKDF scheme from RFC 5869 as an instance allowed by these NIST documents.
Thanks,
Hugo
On Mon, Nov 1, 2010 at 11:11 AM, Polk, William T.
<william.polk <at> nist.gov> wrote:
Folks,
I apparently black-holed an important NIST email last September. NIST has
published a draft specification covering key derivation functions based on
the extraction-then-expansion model we standardized in RFC 5869.
Unfortunately, I failed to forward the request for feedback on the draft to
this list.
The official comment period closed October 30, but the authors were hoping
for more feedback from IETF participants, and have asked me (a second time)
to send the call to the community. The authors have assured me that
comments submitted before November 30 will be received in plenty of time for
the revision process.
Thanks,
Tim Polk
> Call for Comments:
>
> This is a reminder that the comment period for draft SP 800-56C,
> Recommendation for Key Derivation through Extraction-then-Expansion will close
> on October 30, 2010. The announcement and draft can be found at
> http://csrc.nist.gov/publications/PubsDrafts.html#SP-800-56-C
>
> Please submit comments to 800-56Ccomments <at> nist.gov with "Comments on SP
> 800-56C" in the subject line.
_______________________________________________
saag mailing list
saag <at> ietf.org
https://www.ietf.org/mailman/listinfo/saag
<div>
<p>Hi Tim,<br><br>I included the following point in comments I submitted to NIST, yet it may be worth repeating it here. SP 800-56C SEEMS to allow for the use of the technique standardized in RFC 5869. However, to arrive to that conclusion one has to carefully parse SP 800-56C as well as 800-108 and navigate the optional parts of these schemes. To avoid confusion and many questions in the future, I recommend that SP 800-56C (and preferably also the recent draft SP 800-135) EXPLICITLY mention the specific HKDF scheme from RFC 5869 as an instance allowed by these NIST documents.<br><br>Thanks,<br><br>Hugo<br><br></p>
<div class="gmail_quote">On Mon, Nov 1, 2010 at 11:11 AM, Polk, William T. <span dir="ltr"><<a href="mailto:william.polk <at> nist.gov">william.polk <at> nist.gov</a>></span> wrote:<br><blockquote class="gmail_quote">
Folks,<br><br>
I apparently black-holed an important NIST email last September. NIST has<br>
published a draft specification covering key derivation functions based on<br>
the extraction-then-expansion model we standardized in RFC 5869.<br>
Unfortunately, I failed to forward the request for feedback on the draft to<br>
this list.<br><br>
The official comment period closed October 30, but the authors were hoping<br>
for more feedback from IETF participants, and have asked me (a second time)<br>
to send the call to the community. The authors have assured me that<br>
comments submitted before November 30 will be received in plenty of time for<br>
the revision process.<br><br>
Thanks,<br><br>
Tim Polk<br><br><br>
> Call for Comments:<br>
><br>
> This is a reminder that the comment period for draft SP 800-56C,<br>
> Recommendation for Key Derivation through Extraction-then-Expansion will close<br>
> on October 30, 2010. The announcement and draft can be found at<br>
> <a href="http://csrc.nist.gov/publications/PubsDrafts.html#SP-800-56-C" target="_blank">http://csrc.nist.gov/publications/PubsDrafts.html#SP-800-56-C</a><br>
><br>
> Please submit comments to <a href="mailto:800-56Ccomments <at> nist.gov">800-56Ccomments <at> nist.gov</a> with "Comments on SP<br>
> 800-56C" in the subject line.<br><br>
_______________________________________________<br>
saag mailing list<br><a href="mailto:saag <at> ietf.org">saag <at> ietf.org</a><br><a href="https://www.ietf.org/mailman/listinfo/saag" target="_blank">https://www.ietf.org/mailman/listinfo/saag</a><br>
</blockquote>
</div>
<br>
</div>