Re: Next steps on the IPv6 Node requirements draft

Along with removing DES from the "SHALL" list, it looks likely that AES
will be added to the IPSec SHALL requirements, perhaps this draft should
include AES.


john.loughney@nokia.com wrote:
> Hi all,
> I've updated the draft on 4 major points that were discussed at the IETF.  Roughly
> they cover stateful address autoconfig support, DHCP support, MIPv6 support and DES
> support.
> 4) DES support removed:
>  The "ESP DES-CBC Cipher Algorithm With Explicit IV" [RFC-2405] SHOULD NOT be supported.
>  Security issues related to the use of DES are discussed in [DESDIFF], [DESINT],
>  [DESCRACK]. It is still listed as required by the existing IPsec RFCs, but as it is
>  currently viewed as an inherently weak algorithm, and no longer fulfills its intended role.

