Hi Ben, Thanks for this update. I prefer the way you have things in the draft now (outputs of length 256 and 512 bits respectively), primarily for the consistency with HMAC.
Best, Casey ________________________________ From: Ben S3 <[email protected]> Sent: Wednesday, September 9, 2026 8:50 AM To: [email protected] <[email protected]> Subject: [IPsec] Re: I-D Action: draft-ietf-ipsecme-sha3-02.txt Hi IPSECME! This version of the draft contains the following substantive updates: * We removed the use of SHA-3 as a signature hash function. We received feedback expressing a preference for SHAKE over SHA-3 in this context, and we believe SHAKE covers all use cases where one might want to use SHA-3. * The document has been renamed to reflect the fact that it now just specifies use of KMAC and SHAKE. * The document no longer uses customisation strings, instead using the presence of the trailing 0x01 byte to provide domain separation between prf and prf+. This aligns the document with the latest iteration of draft-ietf-ipsecme-ikev2-prf-plus. * Various corrections/clarifications of key sizes, output lengths, and security strengths. We have (at least) one remaining open question, which we'd be interested in the WG's thoughts on: When used as a PRF, the draft currently specifies an output length of 256 bits for KMAC-128 and 512 bits for KMAC-256. This is equal to their respective key lengths, and is analogous to what is done with HMAC-SHA256/HMAC-SHA512. We mainly took this approach for simplicity. Now, if IKE does not rely on the collision resistance of PRF (and we believe it doesn't), then it would be possible to reduce that output length to 128 and 256 bits respectively. This would also let us reduce the key sizes down to 128/256 bits. However, this would mean that any future extension to IKE would need to check it doesn't rely on collision resistance, so it might just be simpler to match what is done with HMAC-SHA2. Either way, interested in the WG's views on this one. Best, Ben, Adam, and Jonathan -----Original Message----- From: [email protected] <[email protected]> Sent: 09 September 2026 13:46 To: [email protected] Cc: [email protected] Subject: [IPsec] I-D Action: draft-ietf-ipsecme-sha3-02.txt Internet-Draft draft-ietf-ipsecme-sha3-02.txt is now available. It is a work item of the IP Security Maintenance and Extensions (IPSECME) WG of the IETF. Title: Use of KMAC and SHAKE in the Internet Key Exchange Protocol Version 2 (IKEv2) and IPsec Authors: Ben Salter Adam Raine Jonathan Cruickshanks Name: draft-ietf-ipsecme-sha3-02.txt Pages: 26 Dates: 2026-09-09 Abstract: This document specifies the use of KMAC128 and KMAC256 within the Internet Key Exchange Version 2 (IKEv2), Encapsulating Security Payload (ESP), and Authentication Header (AH) protocols. These algorithms can be used as integrity protection algorithms for ESP, AH and IKEv2, and as Pseudo-Random Functions (PRFs) for IKEv2. Requirements for supporting signature algorithms in IKEv2 that use SHA3-256, SHA3-384, SHA3-512, SHAKE128 and SHAKE256 are also specified. The IETF datatracker status page for this Internet-Draft is: https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-ietf-ipsecme-sha3%2F&data=05%7C02%7Ccwwynn%40uwe.nsa.gov%7C8056c012271245c78c9508df0e71124d%7Cd61e9a6ffc164f848a3e6eeff33e136b%7C0%7C0%7C639245550955478885%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=K%2B0ifRNgz%2FVaAosels4%2BRioAiLcBvznrnGpm9ajRU1A%3D&reserved=0<https://datatracker.ietf.org/doc/draft-ietf-ipsecme-sha3/> There is also an HTMLized version available at: https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Fdraft-ietf-ipsecme-sha3-02&data=05%7C02%7Ccwwynn%40uwe.nsa.gov%7C8056c012271245c78c9508df0e71124d%7Cd61e9a6ffc164f848a3e6eeff33e136b%7C0%7C0%7C639245550955508344%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=PrjsP%2FFD%2BNYwhtHPjQSf1JkSAvWgFK4jFoWgFEAOTE4%3D&reserved=0<https://datatracker.ietf.org/doc/html/draft-ietf-ipsecme-sha3-02> A diff from the previous version is available at: https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fauthor-tools.ietf.org%2Fiddiff%3Furl2%3Ddraft-ietf-ipsecme-sha3-02&data=05%7C02%7Ccwwynn%40uwe.nsa.gov%7C8056c012271245c78c9508df0e71124d%7Cd61e9a6ffc164f848a3e6eeff33e136b%7C0%7C0%7C639245550955529480%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=yL738CJbOsDqtiL2XxeH%2FaXtYe8Sc9DOGX%2Fom4FpIfs%3D&reserved=0<https://author-tools.ietf.org/iddiff?url2=draft-ietf-ipsecme-sha3-02> Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected] _______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
_______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
