Re: [TLS] WGLC for draft-ietf-tls-ecdhe-psk-aead

2016-12-20 Thread Russ Housley
> This is the working group last call for the "ECDHE_PSK with AES-GCM and > AES-CCM CSs for TLS” draft I am curious about the choice of hash function for TLS_ECDHE_PSK_WITH_AES_256_CCM_8_SHA256. All of the other AES-256 ciphersuites defined in this document that use SHA-384. Why does the one

Re: [TLS] WGLC for draft-ietf-tls-ecdhe-psk-aead

2016-12-20 Thread Martin Thomson
On 21 December 2016 at 01:45, Russ Housley wrote: > I am curious about the choice of hash function for > TLS_ECDHE_PSK_WITH_AES_256_CCM_8_SHA256. All of the other AES-256 > ciphersuites defined in this document that use SHA-384. Why does the one > with a truncated authentication tag use SHA-2