>> Where is Blake2S-based HMAC defined?  RFC 7693 merely says

> Section 3.3 simply says:

>    If a secret key is used (kk > 0), it is padded with zero bytes and
>    set as d[0].  Otherwise, d[0] is the first data block.  The final
>    data block d[dd-1] is also padded with zero to "bb" bytes (16 words).

Thanks, that was the bit I'm missing.

With that info, I have no objection to making Blake2S RECOMMENDED in
Babel-HMAC.  I'm still waiting for more opinions before I make up my mind.

-- Juliusz

_______________________________________________
Babel-users mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/babel-users

Reply via email to