Re: Issue 152: Need crypto protocol agility
From: Pat Calhoun (pacalhou) (pcalhouncisco.com)
Date: Wed, 30 Jul 2008 15:00:06 -0700 (PDT)
Oh right. Making sure that everyone is awake ;-)

PatC 

-----Original Message-----
From: Nathan J. Williams [mailto:nathan.williams [at] thingmagic.com] 
Sent: Wednesday, July 30, 2008 2:18 PM
To: Pat Calhoun (pacalhou)
Cc: Pasi.Eronen [at] nokia.com; Margaret Wasserman; capwap [at] frascone.com
Subject: Re: [Capwap] Issue 152: Need crypto protocol agility

"Pat Calhoun (pacalhou)" <pcalhoun [at] cisco.com> writes:

> 12.1.5.  Use of MD5
>
>    The Image Information Section 4.6.29) message element makes use of
>    MD5 to compute the hash field.  It is important to note that in
order
>    to preserve interoperability with existing CAPWAP implementations,
it
>    was decided to not provide protocol agility.  That said, it is also
>    important to note that the use of MD5 in this context is to create 
> a
                                                            ^^^
                                                            not

>    cryptographically secure hash, but instead to provide a basic
>    checksum value.  Therefore, the use of MD5 is not considered a
>    security vulnerability.
> </text>

Right?

        - Nathan

Results generated by Tiger Technologies using MHonArc.