Re: [Openvpn-devel] Add support for Keying Material Exporter [RFC 5705]

2015-03-09 Thread daniel kubec
Hi Steffan, David and Gert, I fixed bug related to format_hex_ex() for size > 20, removed bracers arround "-keying-material-exporter label len" and added upper bound to the check in options.c. king regards Daniel On 6 March 2015 at 20:44, David Sommerseth wrote: > -BEGIN PGP SIGNED MESSAG

Re: [Openvpn-devel] Add support for Keying Material Exporter [RFC 5705]

2015-03-09 Thread daniel kubec
Hi Gert, There are alot of different use-cases for this standard mechanism and I really thinkin about better explanation in general. I think that some real example will help alot but it requires alot of client+server code of different protocols (so many of do this and that). When you got authenti

Re: [Openvpn-devel] Add support for Keying Material Exporter [RFC 5705]

2015-03-09 Thread Gert Doering
Hi, On Mon, Mar 09, 2015 at 07:26:28PM +0100, daniel kubec wrote: > It is actually well defines mechanism for "crypto/authentication" > plugin developers and they should know what they are doing. > > Maybe Let's try to discuss that using IRC. IRC explanation isn't going to help someone who comes

Re: [Openvpn-devel] Add support for Keying Material Exporter [RFC 5705]

2015-03-09 Thread daniel kubec
Hi, I wanted to discuess (IRC) what exactly I should add to documentation. It's like adding standard, secure and well defined hash-function for use by plugins and then there are (N) different use-cases. "\-keying-material-exporter label len Save Exported Keying Material [RFC5705] of len bytes us