> My reading of the GPSK draft is that the Protected Payload data will
> be integrity protected using the MAC from the combined mode and there
> is the integrity checksum over the entire GPSK-Message.  I think we
> should avoid the multiple MACs.

...

> I am curious about others' opinions on EAX vs. CCM.

We could replace AES-EAX with AES-CBC.  Would address both your concerns?

--
t. charles clancy, ph.d.  |  [EMAIL PROTECTED]  |  www.cs.umd.edu/~clancy

_______________________________________________
Emu mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/emu

Reply via email to