[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: Re: [kmip] KMIP: RNG Proposals
On 14/12/2013 9:51 AM, Burns, Robert wrote: > If we added the following into RNG Parameters that would cover off on what is currently noted in the validation lists: > Prediction Resistance Enabled - Boolean > Derivation Function Used - Boolean > > [<Bob>] I think adding just those two functions is useful. Observation: Prediction resistance applies to all SP800-90(A) DRBGs, whereas the derivation function is only for cipher based DRBGs. > > Also, as an aside, if we are enumerating the various SP800-90(A) DRBG types, I assert we should leave off the Dual_EC DRBGs, if that hasn't already been considered. ;-> I think they should remain with enumeration values specified (like we have for other enumerations) and perhaps we could include a usage guide note on the issue if someone can come up with acceptable wording for such a note. We haven't made any specific recommendations in terms algorithms to not use within KMIP to date and remember we do list DES and things like RC2 within the algorithm list - see 22.214.171.124.13 within the KMIP 1.2 committee specification draft. Tim.