[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Another pothole in ISAKMP/Oakley



Dan,

Regarding:
>  Is this really a pothole in ISAKMP/Oakley?
>> Another pothole of note in ISAKMP is Diffie-Hellman
>> small-subgroup confinement.

Well, it's a problem in Diffie-Hellman itself, on which
ISAKMP/Oakley depends.  Apparently not enough people
know about it.

> Are you suggesting a reference to X9.42 in the ISAKMP/Oakley
> document? Also, for the benefit of those of us who are not
> cryptographers, can you elaborate on the problem of "small
> sub-group confinement" and how ISAKMP/Oakley fails to address it?

Yes.  See my reply to Hilarie's message for more elaboration.

-- David