[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Evaluation: draft-ietf-ipsec-ciph-aes-xcbc-mac - The



I'm a no ob, but have one nit:

   tion.  The classic CBC-MAC algorithm, while secure for messages of a
   pre-selected fixed length, has been shown to be insecure across mes-
   sages of varying lengths such as the type found in typical IP data-
   grams.  In fact, it is trivial to produce forgeries for a second mes-
   sage given the MAC of a prior message.

Might be good to include a reference to some of the work mentioned
above.

Thomas