IPSec Questions

Robert Moskowitz rgm at icsa.net
Tue Aug 10 18:04:51 EDT 1999


At 02:59 PM 8/10/1999 -0500, Tina Bird wrote:
>
>How do you decide whether to use MD5 or SHA-1 for message authentication?
>SHA-1
>has a longer key, but are there any other ways to decide between them?
>
The lengths for HMAC-MD5 and HMAC-SHA1 are truncated to 96 bits per our
cryptographes.

The same cryptographers were concerned about MD5 and have stated that for a
little more computational effort SHA1 preferable.


Robert Moskowitz
ICSA, Inc.
	(248) 968-9809
Fax:	(248) 968-2824
rgm at icsa.net

There's no limit to what can be accomplished 
if it doesn't matter who gets the credit


****************************************************************
TO POST A MESSAGE on this list, send it to vpn at listserv.secnetgroup.com

The VPN FAQ (under construction) is available at
http://kubarb.phsx.ukans.edu/~tbird/FAQ.html

We are currently experiencing "unsubscribe" difficulties.  If you
wish to unsubscribe, please send a message containing the single line
"unsubscribe vpn your-e-mail-address" to owner-vpn at listserv.secnetgroup.com

****************************************************************




More information about the VPN mailing list