Re: [IPsec] Question about RFC 5114

2010-04-06 Thread Joy Latten
On Fri, 2010-03-26 at 19:48 -0700, Scott Fluhrer (sfluhrer) wrote: > > > -Original Message- > > From: ipsec-boun...@ietf.org [mailto:ipsec-boun...@ietf.org] On Behalf > > Of Joy Latten > > Sent: Friday, March 26, 2010 5:25 PM > > To: mlepin...@bbn.com; k...@bbn.com > > Cc: ipsec@ietf.org;

Re: [IPsec] Question about RFC 5114

2010-04-06 Thread Richard Barnes
Thanks so much for the detail. It has helped greatly. I did take a look at NIST SP 800-56A section 5.6.2.4 for validating the public value. I am in learning mode, so I found the 2nd step confusing... 1. Verify that 2 <= y <= p - 2 2. Verify that y^q = 1 (mod p) Are the parenthesis around "mod

Re: [IPsec] Question about RFC 5114

2010-04-06 Thread Joy Latten
On Tue, 2010-04-06 at 12:54 -0400, Richard Barnes wrote: > > Thanks so much for the detail. It has helped greatly. > > I did take a look at NIST SP 800-56A section 5.6.2.4 for validating > > the > > public value. I am in learning mode, so I found the 2nd step > > confusing... > > 1. Verify that 2