crypto algorithms for DTLS
From: Abhijit Choudhury (achoudhu) (achoudhucisco.com)
Date: Tue, 8 Jul 2008 15:01:51 -0700 (PDT)
Folks,

The issue of using AES-GCM as a cipher-suite for CAPWAP/DTLS
was discussed in the list about a year ago.  (Please refer
to CAPWAP issue 7
(http://www.capwap.org/cgi-bin/roundup.cgi/CAPWAP/issue7)

Due to the use of DTLS, we were stuck with TLS ciphersuites.  
To use GCM we would require a TLS GCM ciphersuite.  We discussed this
at an ad-hoc meeting, and decided to defer this feature, as GCM was not
a TLS ciphersuite, and there was no document to reference.

However, since that time, use of AES-GCM has been approved in the
TLS working group, and we have an approved draft 
https://datatracker.ietf.org/idtracker/draft-ietf-tls-rsa-aes-gcm/

As noted in the original email, there is a lot of momentum
behind this crypto algorithm, and it results in significant
improvements in throughput in either HW or SW implementations.

Could we address this issue in the current spec and make
AES-GCM an ciphersuite that can be used with CAPWAP/DTLS ?

Thanks,
Abhijit
 
 

Results generated by Tiger Technologies using MHonArc.