Feedback about recommended AES modes #2509
Labels
1) Discussion ongoing
Issue is opened and assigned but no clear proposal yet
AppendixV
Appendix with crypto details
_5.0 - Not blocker
This issue does not block 5.0 so if it gets addressed then great, if not then fine.
Feedback from Bart Preneel related to AES modes (other aspects are discussed in #2495):
Some notes/questions:
CCM-8 is listed here (see Crypto Appendix - Restrictions on CCM8 #2413), so maybe it makese sense to keep this.
OCB is not listed. We should probably add it.
CBC is not mentioned in this feedback but is currently approved in the document. Shall we do something about it? For what it's worth, it is still allowed by NIST / FIPS. Should we list it are "approved but discouraged / legacy" ? (see Appendix Crypto - Allowed mechanisms and requirement levels #2398 (comment))
Shall we explicitly talk about nonce reuse in AES-GCM somewhere ? We already have:
The text was updated successfully, but these errors were encountered: