cfrg / draft-irtf-cfrg-aegis-aead

Specification for the AEGIS family of authenticated encryption algorithms.
https://cfrg.github.io/draft-irtf-cfrg-aegis-aead/draft-irtf-cfrg-aegis-aead.html
Other
10 stars 2 forks source link

Require SHA512 for the variants with 256-bit security? #20

Closed jedisct1 closed 10 months ago

jedisct1 commented 11 months ago

It's 2am and I need to get some sleep before reading this, but @emanjon just dropped this:

https://eprint.iacr.org/2023/913.pdf

For AEGIS-256X, this is not an issue, as the IANA request hasn't been made yet.

For TLS_AEGIS_256_SHA384, I don't know if the suite name can be updated (that would be a breaking change for existing implementations, but this is fine as the document is still a draft), or if we should ask for a new one.

samuel-lucas6 commented 11 months ago

I haven't read the full paper yet, but it does seem like that should be swapped. Guess Sabrina Tanamal who assigned that needs to be contacted/asked.

jedisct1 commented 11 months ago

I reached out to Sabrina. Waiting for her response.

jedisct1 commented 10 months ago

IANA updated the entry: https://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml#tls-parameters-4

I'm going to inform/update existing implementations.